CVE-2024-33836 Information

Description

In the module \JA Marketplace\ (jamarketplace) up to version 9.0.1 from JA Module for PrestaShop a guest can upload files with extensions .php. In version 6.X the method JmarketplaceproductModuleFrontController::init() and in version 8.X the method JmarketplaceSellerproductModuleFrontController::init() allow upload of .php files which will lead to a critical vulnerability.

Reference

https://github.com/friends-of-presta/security-advisories/blob/main/_posts/2024-06-18-jamarketplace.md

Share on: