cve/2024/CVE-2024-34990.md
2025-09-29 21:09:30 +02:00

970 B

CVE-2024-34990

Description

In the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop, a customer can upload .php files. Methods HelpdeskHelpdeskModuleFrontController::submitTicket() and HelpdeskHelpdeskModuleFrontController::replyTicket() allow upload of .php files on a predictable path for connected customers.

POC

Reference

Github

No PoCs found on GitHub currently.