PrestaShop 的 Google Merchant Center Feed(gmfeed)模块存在未认证任意文件写入漏洞,影响 feed.php 端点。未经身份验证的攻击者可以发送精心构造的请求,通过请求参数控制输出文件的文件名、路径、扩展名和内容。由于缺乏身份验证和输入验证机制,该请求会被成功处理,从而允许攻击者写入并执行任意 PHP 代码,最终导致远程代码执行(RCE)。 该问题已在版本 2.3.9 中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MyPresta | Google Merchant Center Feed | 1.9.1≤ 2.3.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MyPresta | Google Merchant Center Feed | 1.9.1 ~ 2.3.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet