Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-41651


An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disputed by multiple parties, who report that exploitation requires that an attacker be able to hijack network requests made by an admin user (who, by design, is allowed to change the code that is running on the server).


Published

2024-08-12T17:15:17.373

Last Modified

2024-10-09T18:15:05.387

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

Weaknesses
  • Type: Primary
    CWE-918
  • Type: Secondary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application prestashop prestashop ≤ 8.1.7 Yes

References