← back
CVE-2024-41651criticalCWE-94

CVE-2024-41651

48Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9.8epss 1.3%
from disclosure to weapon0 days
Published on NVDAug 12
1st PoCAug 8
exploitation probability
1.3%top 33% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disputed by multiple parties, who report that exploitation requires that an attacker be able to hijack network requests made by an admin user (who, by design, is allowed to change the code that is running on the server).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.