First published: Thu Dec 05 2019(Updated: )
reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute arbitrary code by uploading a .php file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Stock API integration | =4.8 | |
Prestashop | =1.6 | |
Prestashop | =1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19594 has a high severity rating due to the potential for remote code execution.
To fix CVE-2019-19594, update the Adobe Stock API Integration module to the latest version and ensure that file upload restrictions are in place.
CVE-2019-19594 affects PrestaShop versions 1.6 and 1.7 as well as the Adobe Stock API Integration module version 4.8.
CVE-2019-19594 is primarily a remote code execution vulnerability that allows attackers to upload malicious PHP files.
Yes, CVE-2019-19594 can potentially be exploited by unauthenticated users, allowing arbitrary code execution.