S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2018-8823 Scanner

CVE-2018-8823 Scanner - Remote Code Execution (RCE) vulnerability in PrestaShop Responsive Mega Menu Module

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
4.3k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-8823
9.8
CVSS

modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to execute arbitrary PHP code via the code parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 18, 2026View on NVD →
Detail

The Responsive Mega Menu Module is a widely used add-on for PrestaShop, enhancing online stores with sophisticated menu options like horizontal, vertical, and dropdown menus. Online retailers predominantly use it to improve site navigation and user experience. PrestaShop users, from small businesses to larger companies, integrate this module to provide visually appealing and functional menu systems to their shoppers. The module's flexibility in design and functionality makes it popular for boosting the customer shopping experience. However, managing security vulnerabilities in these integrations is crucial to avoid compromising customer data. Thus, understanding the risks associated with plugin installations is important for developers and site administrators alike.

The detected vulnerability allows remote code execution in the Responsive Mega Menu module, presenting a significant security risk. It endangers sensitive information and can compromise the website’s integrity. Through an improperly sanitized 'code' parameter, attackers can inject harmful code, gaining unauthorized access and control over the affected system. This vulnerability highlights the potential dangers of unsanitized input fields in widely used e-commerce solutions. Site administrators must vigilantly deploy security best practices to prevent exploitation. Consequently, understanding the technical and procedural errors leading to this vulnerability is essential for prevention.

This vulnerability specifically involves arbitrary function calls by manipulating the 'code' parameter in the request to 'ajax_phpcode.php'. The lack of proper input validation allows attackers to execute unwanted commands or injection scripts. Successful exploitation can lead to significant impacts, including complete control of the module functionality. Attackers often target this vulnerability to manipulate SQL commands, compromising the database's confidentiality, integrity, and availability. This vulnerability provides a clear pathway for attackers to introduce malicious scripts, posing a continuing risk if unaddressed. The exposure highlights the critical need for regular updates and patches.

If exploited, this vulnerability allows an attacker to execute arbitrary code on the server hosting the PrestaShop instance. This could result in unauthorized data access, data theft, and severe disruption of store operations. Furthermore, attackers could manipulate e-commerce transaction data, leading to financial losses and unauthorized purchases. The exploitation might also serve as a vector for broader cyber-attacks, utilizing the compromised server as a launching point. Therefore, unaddressed vulnerabilities can severely impact the reputation and profitability of online stores. Regular monitoring and patching are vital to safeguard against such risks.

REFERENCES

Solution Advice
  • Update the PrestaShop Responsive Mega Menu Module to the latest patched version.
  • Implement validation and sanitation on all incoming data to prevent code injections.
  • Regularly monitor and audit server logs for unusual activity that may indicate an attempted exploitation.
  • Employ a web application firewall to block malicious requests automatically.
  • Conduct regular security assessments and vulnerability tests on the module and associated plugins.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-8823 Scanner - Remote Code Execution (RCE) vulnerability in PrestaShop Responsive Mega Menu Module | S4E