← Back

CVE-2024-41651

nvd nist
Published: Aug 12, 2024Modified: Jun 17, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disputed by multiple parties, who report that exploitation requires that an attacker be able to hijack network requests made by an admin user (who, by design, is allowed to change the code that is running on the server).

Affected (1)

1 product
Prestashop
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 8.1.7

References (1)

Source: cve@mitre.org
ExploitThird Party Advisory

Timeline

No history available yet.