Description
PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ directory.
Remediation
References
Related Vulnerabilities
Atlassian Jira Missing Authentication for Critical Function Vulnerability (CVE-2019-8449)
WordPress Plugin Zoho CRM Lead Magnet Unspecified Vulnerability (1.7.2.9)
WordPress Plugin Relevant-Related Posts by BestWebSoft Cross-Site Scripting (1.1.9)
Oracle Database Server CVE-2009-1991 Vulnerability (CVE-2009-1991)