CVE-2024-41651

An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disputed by multiple parties, who report that exploitation requires that an attacker be able to hijack network requests made by an admin user (who, by design, is allowed to change the code that is running on the server).
References
Link Resource
https://github.com/Fckroun/CVE-2024-41651/tree/main Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-08-12 17:15

Updated : 2024-10-09 18:15


NVD link : CVE-2024-41651

Mitre link : CVE-2024-41651

CVE.ORG link : CVE-2024-41651


JSON object : View

Products Affected

prestashop

  • prestashop
CWE
CWE-918

Server-Side Request Forgery (SSRF)

CWE-94

Improper Control of Generation of Code ('Code Injection')