CVE-2024-25846: Myprestamodules Product Catalog (csv, Excel) Import

Critical severity, CVSS 9.1. EPSS: 0.8% chance of exploitation in the next 30 days.

In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php.

Affected products

  • Myprestamodules Product Catalog (csv, Excel) Import: up to and including 6.7.0

Published 2024-02-27. Last modified 2026-06-17.