CVE-2018-8823: Code Injection
Published Mar 28, 2018
·Updated
modules/bamegamenu/ajaxphpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to execute arbitrary PHP code via the code parameter.
Affected Software
2 affected components
Responsive Mega Menu Pro Project Responsive Mega Menu Pro Prestashop=1.0.32
Prestashop PrestaShop>=1.5.5.0<=1.7.2.5
Event History
Mar 28, 2018
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·02:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-8823?
CVE-2018-8823 is classified as a critical vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2018-8823?
To fix CVE-2018-8823, upgrade the Responsive Mega Menu Pro module to a version later than 1.0.32.
3
Which versions of PrestaShop are affected by CVE-2018-8823?
CVE-2018-8823 affects PrestaShop versions from 1.5.5.0 through 1.7.2.5.
4
Can CVE-2018-8823 be exploited remotely?
Yes, CVE-2018-8823 can be exploited remotely by attackers through the 'code' parameter.
5
What components are vulnerable in CVE-2018-8823?
The vulnerable component is the ajax_phpcode.php file within the Responsive Mega Menu Pro module.