Vulnerability Description
In the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop, a customer can upload .php files. Methods `HelpdeskHelpdeskModuleFrontController::submitTicket()` and `HelpdeskHelpdeskModuleFrontController::replyTicket()` allow upload of .php files on a predictable path for connected customers.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/friends-of-presta/security-advisories/blob/main/_posts/2024-0
- https://github.com/friends-of-presta/security-advisories/blob/main/_posts/2024-0
FAQ
What is CVE-2024-34990?
CVE-2024-34990 is a vulnerability with a CVSS score of 10.0 (CRITICAL). In the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop, a customer can upload .php files. Methods `HelpdeskHelpdeskModuleFrontCon...
How severe is CVE-2024-34990?
CVE-2024-34990 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-34990?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.