Products
PrestaShop Help Desk - Customer Support Management System (helpdesk) module
- up to 2.4.0
Source
cve@mitre.org
Tags
CVE-2024-34990 details
Published : June 19, 2024, 9:15 p.m.
Last Modified : June 19, 2024, 9:15 p.m.
Last Modified : June 19, 2024, 9:15 p.m.
Description
In the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop, a customer can upload .php files. Methods `HelpdeskHelpdeskModuleFrontController::submitTicket()` and `HelpdeskHelpdeskModuleFrontController::replyTicket()` allow upload of .php files on a predictable path for connected customers.
CVSS Score
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|
References
URL | Source |
---|---|
https://github.com/friends-of-presta/security-advisories/blob/main/_posts/2024-06-18-helpdesk.md | cve@mitre.org |
This website uses the NVD API, but is not approved or certified by it.