modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 up to and including 1.6.1.18 allows remote malicious users to execute arbitrary code by uploading a .phtml file.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
attribute wizard project attribute wizard 1.6.9 |