Aller au contenu

Fiche vulnérabilité

CVE-2024-41651 : faille élevée prestashop prestashop (CVSS 8.1)

Description

An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disputed by multiple parties, who report that exploitation requires that an attacker be able to hijack network requests made by an admin user (who, by design, is allowed to change the code that is running on the server).

En bref

Sévérité
Élevée (CVSS 8.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
12 août 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • prestashop prestashop

Références

Rechercher une autre vulnérabilité dans la base CVE