Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability in a Google Merchant Center module for PrestaShop allows unauthenticated attackers to write and execute arbitrary code, potentially leading to full system compromise. This issue arises from a lack of authentication and input validation in the feed processing endpoint, enabling attackers to control file names, paths, extensions, and content.
- Unauthenticated code execution in e-commerce module.
- Critical flaw risks compromise of merchant data.
- Confirm relevance and potential exposure.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can exploit this vulnerability by sending a specially crafted request to the `feed.php` endpoint. This request manipulates parameters to control the filename, path, extension, and content of a file, ultimately allowing the attacker to write and execute arbitrary PHP code on the server, leading to remote code execution.
- No authentication required for access.
- Manipulated request parameters trigger file write.
- Remote code execution is the likely outcome.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an unauthenticated attacker to write arbitrary files to the server by controlling the output file name, path, extension, and content through request parameters. When supported by the advisory, this could lead to the execution of arbitrary PHP code on the affected system.
- Arbitrary file write to server.
- Unauthenticated request with crafted parameters.
- Remote code execution on server.
Operational Fix
Recommended remediation, mitigation, and detection steps
The PrestaShop Google Merchant Center Feed module's arbitrary file write vulnerability likely falls under the responsibility of platform or application owners who manage the e-commerce site. The first step is to identify all instances of the affected module, determine their reachability and business criticality, and confirm the accountable owner before planning remediation.
- Platform or application owners should manage.
- Verify module reachability and business criticality.
- Plan remediation based on confirmed risk.