CVE-2019-19595: Malicious File Upload
reset/modules/advancedformmakeredit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows remote attackers to execute arbitrary code by uploading a .php file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19595?
CVE-2019-19595 has a CVSS score that categorizes it as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2019-19595?
To fix CVE-2019-19595, update the Adobe Stock API integration to the latest version or remove the vulnerable module from your PrestaShop installation.
Who is affected by CVE-2019-19595?
CVE-2019-19595 affects users of Adobe Stock API integration version 4.8 and PrestaShop versions 1.6 and 1.7.
What are the implications of exploiting CVE-2019-19595?
Exploiting CVE-2019-19595 can allow remote attackers to upload malicious PHP files and execute arbitrary code on the server.
Is there a workaround for CVE-2019-19595?
A possible workaround for CVE-2019-19595 is to restrict file upload permissions or disable the multiupload functionality in the affected modules.