Description
modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute arbitrary code by uploading a php file via modules/orderfiles/upload.php with auptype equal to product (for upload destinations under modules/productfiles), order (for upload destinations under modules/files), or cart (for upload destinations under modules/cartfiles).
Remediation
References
Related Vulnerabilities
Grafana Insufficiently Protected Credentials Vulnerability (CVE-2019-15635)
WordPress 4.7.x Multiple Vulnerabilities (4.7 - 4.7.24)
WordPress 6.0.x Cross-Site Scripting (6.0 - 6.0.7)
Oracle JRE CVE-2014-0456 Vulnerability (CVE-2014-0456)
PostgreSQL Incorrect Authorization Vulnerability (CVE-2018-10925)