helpdesk- PrestaShop module vulnerability (CVE-2024-34990)

Modulehelpdesk

Score

10 Critical

Date publish

19-06-2024

Versiones afectadas

  • Less than 2.4.0

Description

In the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop, a customer can upload .php files. Methods `HelpdeskHelpdeskModuleFrontController::submitTicket()` and `HelpdeskHelpdeskModuleFrontController::replyTicket()` allow upload of .php files on a predictable path for connected customers.

References

Metrics

cvssMetricV31
source134c704f-9b21-4f2e-91b3-4a467353bcc0
typeSecondary
version3.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
baseScore10
baseSeverityCRITICAL
attackVectorNETWORK
attackComplexityLOW
privilegesRequiredNONE
userInteractionNONE
scopeCHANGED
confidentialityImpactHIGH
integrityImpactHIGH
availabilityImpactHIGH
exploitabilityScore3.9
impactScore6
Scroll al inicio