vendor:
Prestashop
by:
Sivanesh Ashok
9.8
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: Prestashop
Affected Version From: 1.7.6.4
Affected Version To: 1.7.6.4
Patch Exists: YES
Related CWE: N/A
CPE: a:prestashop:prestashop
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 / XAMPP
2020
Prestashop <= 1.7.6.4 single-click RCE exploit
This exploit allows an attacker to execute arbitrary code on a vulnerable Prestashop version 1.7.6.4 and below. The exploit works by sending a malicious SVG file to the target server, which is then processed by the server and executes the code contained in the SVG file. The code in the SVG file contains a malicious URL which is used to import a malicious theme file, which can then be used to execute arbitrary code on the target server.
Mitigation:
Upgrade to the latest version of Prestashop, and ensure that all security patches are applied.