CVE-2024-26469

Server-Side Request Forgery (SSRF) vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attackers to cause a denial of service (DoS) and escalate privileges via the url parameter in the postProcess() method.
Configurations

No configuration.

History

04 Dec 2024, 21:15

Type Values Removed Values Added
CWE CWE-352
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1

21 Nov 2024, 09:02

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de Server-Side Request Forgery (SSRF) en el módulo "Product Designer" (productdesigner) de Tunis Soft para PrestaShop anterior a la versión 1.178.36, permite a atacantes remotos provocar una denegación de servicio (DoS) y escalar privilegios a través del parámetro url en el postProcess () método.
References () https://github.com/friends-of-presta/security-advisories/blob/main/_posts/2024-02-29-productdesigner-918.md - () https://github.com/friends-of-presta/security-advisories/blob/main/_posts/2024-02-29-productdesigner-918.md -

03 Mar 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-03 10:15

Updated : 2024-12-04 21:15


NVD link : CVE-2024-26469

Mitre link : CVE-2024-26469

CVE.ORG link : CVE-2024-26469


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)