CVE-2024-33836

In the module "JA Marketplace" (jamarketplace) up to version 9.0.1 from JA Module for PrestaShop, a guest can upload files with extensions .php. In version 6.X, the method `JmarketplaceproductModuleFrontController::init()` and in version 8.X, the method `JmarketplaceSellerproductModuleFrontController::init()` allow upload of .php files, which will lead to a critical vulnerability.
Configurations

No configuration.

History

21 Nov 2024, 09:17

Type Values Removed Values Added
References () https://github.com/friends-of-presta/security-advisories/blob/main/_posts/2024-06-18-jamarketplace.md - () https://github.com/friends-of-presta/security-advisories/blob/main/_posts/2024-06-18-jamarketplace.md -

03 Jul 2024, 01:58

Type Values Removed Values Added
CWE CWE-434
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

20 Jun 2024, 12:43

Type Values Removed Values Added
Summary
  • (es) En el módulo "JA Marketplace" (jamarketplace) hasta la versión 9.0.1 del Módulo JA para PrestaShop, un invitado puede cargar archivos con extensiones .php. En la versión 6.X, el método `JmarketplaceproductModuleFrontController::init()` y en la versión 8.X, el método `JmarketplaceSellerproductModuleFrontController::init()` permiten cargar archivos .php, lo que conducirá a una vulnerabilidad crítica.

19 Jun 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-19 21:15

Updated : 2024-11-21 09:17


NVD link : CVE-2024-33836

Mitre link : CVE-2024-33836

CVE.ORG link : CVE-2024-33836


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type