In the module "JA Marketplace"... CVE-2024-33836

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

In the module "JA Marketplace" (jamarketplace) up to version 9.0.1 from JA Module for PrestaShop, a guest can upload files with extensions .php. In version 6.X, the method `JmarketplaceproductModuleFrontController::init()` and in version 8.X, the method `JmarketplaceSellerproductModuleFrontController::init()` allow upload of .php files, which will lead to a critical vulnerability.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息