S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Feb 10, 2024

CVE-2018-10942 Scanner

Detects 'Arbitrary File Upload' vulnerability in Prestashop AttributeWizardPro Module affects v. 1.6.9.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-10942
9.8
CVSS

modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to execute arbitrary code by uploading a .phtml file.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Safeguarding PrestaShop with CVE-2018-10942 Vulnerability Scanner

PrestaShop AttributeWizardPro Module Use

The PrestaShop AttributeWizardPro Module is a crucial component for online stores using PrestaShop. It enhances the product listing capabilities, allowing for detailed and customized product attribute displays. This module is pivotal for online retailers to present a variety of product options efficiently, improving customer experience and potentially boosting sales.

CVE-2018-10942 Vulnerability Explained

CVE-2018-10942 exposes a critical Arbitrary File Upload vulnerability in version 1.6.9 of the PrestaShop AttributeWizardPro Module. It enables remote attackers to upload dangerous file types, like .phtml, which can execute arbitrary code, posing a significant security threat.

Consequences of Exploitation

If exploited, this vulnerability can lead to severe consequences, such as website compromise, unauthorized access to sensitive data, and potential spread of malware. The breach could disrupt business operations, erode customer trust, and result in financial losses and legal implications.

Benefits of using S4E

For those not yet on the S4E platform, this vulnerability underscores the importance of Continuous Threat Exposure Management services. The platform's dedicated scanner for CVE-2018-10942 assists in early detection and provides critical insights for safeguarding digital assets.

 

References

Solution Advice
  • Update the Module: Ensure the AttributeWizardPro Module is updated to the latest version.
  • Regular Security Audits: Conduct routine checks for vulnerabilities in your web assets.
  • Implement File Upload Security Measures: Use security plugins or custom code to restrict file types and sizes.
  • Monitor and Review User Activities: Keep an eye on user activities, especially any abnormal patterns like spontaneous account creation.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-10942 scanner - Arbitrary File Upload vulnerability in Prestashop AttributeWizardPro Module | S4E