CVE-2026-85520criticalexploração observadaCWE-73

CVE-2026-85520: falha crítica em MyPresta Google Merchant Center Feed

Unauthenticated arbitrary file write leading to RCE in gmfeed PrestaShop module

Publicada em

70Vexday Risk Score

Priorize a correção. Ela exploração observada pelo VulnCheck e tem prova de conceito pública.

ssvc Actcvss 9.3epss 1.0%
da publicação à arma0 dias
Publicada no NVD29 de set.
1ª PoC29 de set.
VulnCheck29 de set.
probabilidade de exploração
1.0%top 39% das CVEs
exploração observada
simVulnCheck
2 exploit(s) público(s)
Google Merchant Center Feed (gmfeed) module for PrestaShop is vulnerable to unauthenticated arbitrary file write in the feed.php endpoint. An unauthenticated attacker can send a crafted request that controls the output file name, path, extension, and content through request parameters. Due to the lack of authentication and input validation, the request is processed successfully, allowing an attacker to write and execute arbitrary PHP code, resulting in remote code execution (RCE). This issue was fixed in version 2.3.9.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.