Description
PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ directory.
Remediation
References
Related Vulnerabilities
phpBB Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-5502)
SharePoint Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-1103)
WordPress Plugin The Plus Addons for Elementor Security Bypass (4.1.6)
WordPress Plugin Gallery-Photo Albums-Portfolio Cross-Site Scripting (1.3.47)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-1902)