CVE-2019-19594: Malicious File Upload
reset/modules/fotoliaFoto/multiupload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute arbitrary code by uploading a .php file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19594?
CVE-2019-19594 has a high severity rating due to the potential for remote code execution.
How do I fix CVE-2019-19594?
To fix CVE-2019-19594, update the Adobe Stock API Integration module to the latest version and ensure that file upload restrictions are in place.
What systems are affected by CVE-2019-19594?
CVE-2019-19594 affects PrestaShop versions 1.6 and 1.7 as well as the Adobe Stock API Integration module version 4.8.
What type of vulnerability is CVE-2019-19594?
CVE-2019-19594 is primarily a remote code execution vulnerability that allows attackers to upload malicious PHP files.
Can CVE-2019-19594 be exploited without authentication?
Yes, CVE-2019-19594 can potentially be exploited by unauthenticated users, allowing arbitrary code execution.