CVE-2024-24307: Path Traversal
Path Traversal vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows a remote attacker to escalate privileges and obtain sensitive information via the ajaxProcessCropImage() method.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24307?
CVE-2024-24307 has a high severity rating due to its potential to allow privilege escalation and exposure of sensitive information.
How do I fix CVE-2024-24307?
To fix CVE-2024-24307, update the Tunis Soft Product Designer and PrestaShop to versions 1.178.36 or later.
Who does CVE-2024-24307 affect?
CVE-2024-24307 affects users of the Tunis Soft Product Designer module for PrestaShop prior to version 1.178.36.
What kind of attacks can CVE-2024-24307 facilitate?
CVE-2024-24307 can facilitate remote attacks that lead to privilege escalation and unauthorized access to sensitive data.
Is CVE-2024-24307 still exploitable?
CVE-2024-24307 is potentially exploitable in instances running affected versions of the Tunis Soft Product Designer and PrestaShop.