Description
modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to execute arbitrary PHP code via the code parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP HTML Sitemap Cross-Site Request Forgery (1.2)
WordPress Plugin Timber Cross-Site Scripting (1.2.2)
WordPress Plugin Share, Print and PDF Products for WooCommerce Security Bypass (2.7.2)
WordPress Plugin Network Publisher 'networkpub_key' Parameter Cross-Site Scripting (5.0.1)
IBM RTC Improper Privilege Management Vulnerability (CVE-2021-29774)