CVE-2024-34990: Malicious File Upload
In the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop, a customer can upload .php files. Methods HelpdeskHelpdeskModuleFrontController::submitTicket() and HelpdeskHelpdeskModuleFrontController::replyTicket() allow upload of .php files on a predictable path for connected customers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34990?
CVE-2024-34990 is considered a high severity vulnerability due to its ability to allow the upload of executable PHP files by customers.
How do I fix CVE-2024-34990?
To fix CVE-2024-34990, upgrade the Help Desk - Customer Support Management System to version 2.4.1 or later.
Who is affected by CVE-2024-34990?
CVE-2024-34990 affects users of the FME Modules Help Desk - Customer Support Management System up to version 2.4.0.
What versions of PrestaShop are vulnerable to CVE-2024-34990?
CVE-2024-34990 specifically affects the FME Modules Help Desk and does not directly indicate a vulnerability in PrestaShop itself.
What actions should I take to mitigate CVE-2024-34990?
To mitigate CVE-2024-34990, ensure that your Help Desk module is up to date and consider restricting file uploads.