漏洞描述
The 'Responsive Mega Menu' module for PrestaShop is prone to a remote code execution and SQL injection vulnerability. modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop allows remote attackers to execute an SQL injection or remote code execution through function calls in the code parameter.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
vulners.comhttps://vulners.com/openvas/OPENVAS:1361412562310144185↗www.openservis.czhttps://www.openservis.cz/prestashop-blog/nejcastejsi-utoky-v-roce-2023-seznam-deravych-modulu-nemate-nejaky-z-nich-na-e-shopu-i-vy/↗github.comhttps://github.com/advisories/GHSA-q937-6mg8-6rgc↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2018-8823↗github.comhttps://github.com/zapalm/prestashop-security-vulnerability-checker↗