Description
PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ directory.
Remediation
References
Related Vulnerabilities
WordPress Plugin Real WYSIWYG Cross-Site Scripting (0.0.2)
LimeSurvey Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-48008)
WordPress Plugin MAC PHOTO GALLERY Multiple Security Bypass Vulnerabilities (3.0)
SharePoint Download of Code Without Integrity Check Vulnerability (CVE-2020-1576)