
CVE-2024-41651
This document outlines a Blind SSRF to RCE exploit on a fresh PrestaShop 8.1.7 docker installation.
ps_facetedsearchPrepare the Malicious File:
pwn3ed_bayram.txt). Note: Shells could also be popped.


Upgrade the Module:

Intercept and Modify the Request:

source parameter to point to the server hosting your malicious zip file.

Before Exploit:

After Exploit:
pwn3ed_bayram.txt is successfully created in the root directory.
