CVE-2018-10942
40Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 6.3%
from disclosure to weapon
Published on NVDMay 10
VulnCheck+2241d
exploitation probability
6.3%top 7% of all CVEs
observed exploitation
yesVulnCheck
modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to execute arbitrary code by uploading a .phtml file.
Affected products
n/a · n/a