First published: Tue Feb 27 2024(Updated: )
In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MyPrestaModules Product Catalog (CSV, Excel) Import | <=6.7.0 | |
Prestashop |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25846 allows unauthenticated users to upload PHP files, potentially leading to remote code execution on the server.
To fix CVE-2024-25846, upgrade the 'Product Catalog (CSV, Excel) Import' module to version 6.7.1 or later.
CVE-2024-25846 affects versions of the Product Catalog (CSV, Excel) Import module up to and including version 6.7.0.
CVE-2024-25846 is specifically a vulnerability in the 'Product Catalog (CSV, Excel) Import' module for PrestaShop.
The vendor responsible for the affected Product Catalog module is MyPrestaModules.