CVE-2024-28396: Code Injection
Published Mar 20, 2024
·Updated
An issue in MyPrestaModules ordersexport v.6.0.2 and before allows a remote attacker to execute arbitrary code via the download.php component.
Affected Software
2 affected components
MyPrestaModules ordersexport<6.0.2
MyPrestaModules Orders \(csv\, Excel\) Export Pro Prestashop<=6.0.2
Event History
Mar 20, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-28396?
The severity of CVE-2024-28396 is high due to its potential to allow remote code execution.
2
How do I fix CVE-2024-28396?
To fix CVE-2024-28396, update MyPrestaModules ordersexport to version 6.0.3 or later.
3
What is affected by CVE-2024-28396?
CVE-2024-28396 affects MyPrestaModules ordersexport versions 6.0.2 and earlier.
4
Can CVE-2024-28396 allow unauthorized access?
Yes, CVE-2024-28396 can be exploited by remote attackers to execute arbitrary code, leading to unauthorized access.
5
How can I determine if I am using a vulnerable version related to CVE-2024-28396?
You can determine your version of MyPrestaModules ordersexport by checking the module settings in your PrestaShop admin panel.