CVE-2024-33836 Information
Jun 20, 2024
cve
Description
In the module \JA Marketplace\ (jamarketplace) up to version 9.0.1 from JA Module for PrestaShop a guest can upload files with extensions .php. In version 6.X the method JmarketplaceproductModuleFrontController::init() and in version 8.X the method JmarketplaceSellerproductModuleFrontController::init() allow upload of .php files which will lead to a critical vulnerability.