CVE-2024-25846: Malicious File Upload
Published Feb 27, 2024
·Updated
In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php.
Affected Software
3 affected components
MyPrestaModules Product Catalog (CSV, Excel) Import<=6.7.0
Prestashop PrestaShop
MyPrestaModules Product Catalog \(csv\, Excel\) Import Prestashop<=6.7.0
Event History
Feb 27, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What are the security implications of CVE-2024-25846?
CVE-2024-25846 allows unauthenticated users to upload PHP files, potentially leading to remote code execution on the server.
2
How can I mitigate CVE-2024-25846 in my PrestaShop installation?
To fix CVE-2024-25846, upgrade the 'Product Catalog (CSV, Excel) Import' module to version 6.7.1 or later.
3
Which versions of the Product Catalog module are affected by CVE-2024-25846?
CVE-2024-25846 affects versions of the Product Catalog (CSV, Excel) Import module up to and including version 6.7.0.
4
Is CVE-2024-25846 specific to PrestaShop?
CVE-2024-25846 is specifically a vulnerability in the 'Product Catalog (CSV, Excel) Import' module for PrestaShop.
5
Who is the vendor responsible for the Product Catalog module affected by CVE-2024-25846?
The vendor responsible for the affected Product Catalog module is MyPrestaModules.