We have identified that some autoupgrade module ZIP archives have been built with phpunit dev dependencies. PHPUnit contains a php script that would allow, on a webserver, an attacker to perform a RCE.
This vulnerability impacts
You can read PrestaShop official statement about this vulnerability here.
In the security patch, we look for the unwanted vendor/phpunit folder and remove it if we find it. This allows users to fix the security issue when upgrading.
Users can also simply remove the unwanted vendor/phpunit folder.
https://nvd.nist.gov/vuln/detail/CVE-2017-9841
If you have any questions or comments about this advisory, email us at security@prestashop.com
{
"cwe_ids": [],
"github_reviewed": true,
"github_reviewed_at": "2020-01-08T03:06:57Z",
"nvd_published_at": null,
"severity": "HIGH"
}