CVE-2024-28390: Critical severity advanced plugins ultimate image tool vulnerability
An issue in Advanced Plugins ultimateimagetool module for PrestaShop before v.2.2.01, allows a remote attacker to escalate privileges and obtain sensitive information via Improper Access Control.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28390?
CVE-2024-28390 is classified as a high-severity vulnerability due to its potential for privilege escalation and sensitive data exposure.
What systems are affected by CVE-2024-28390?
CVE-2024-28390 affects versions of Advanced Plugins ultimateimagetool prior to 2.2.01 and PrestaShop prior to 2.2.01.
How do I fix CVE-2024-28390?
To fix CVE-2024-28390, update the Advanced Plugins ultimateimagetool module and PrestaShop to version 2.2.01 or later.
What type of attack does CVE-2024-28390 allow?
CVE-2024-28390 allows remote attackers to escalate privileges and obtain sensitive information due to improper access control.
Is there a workaround for CVE-2024-28390 if I cannot update?
As of now, there are no reported workarounds for mitigating CVE-2024-28390; updating to the latest version is recommended.