
🚨 CVE-2026-85520 PoC Released 🔴 Unauthenticated Arbitrary File Write → RCE 📌 PrestaShop Google Merchant Center Feed PoC & technical details: https://pocbit.org/pocs/cve-2026-85520
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Google Merchant Center Feed (gmfeed) module for PrestaShop is vulnerable to unauthenticated arbitrary file write in the feed.php endpoint. An unauthenticated attacker can send a crafted request that controls the output file name, path, extension, and content through request parameters. Due to the lack of authentication and input validation, the request is processed successfully, allowing an attacker to write and execute arbitrary PHP code, resulting in remote code execution (RCE). This issue was fixed in version 2.3.9.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE

🚨 CVE-2026-85520 PoC Released 🔴 Unauthenticated Arbitrary File Write → RCE 📌 PrestaShop Google Merchant Center Feed PoC & technical details: https://pocbit.org/pocs/cve-2026-85520

#schwachstellen PrestaShop gmfeed: Kritische RCE-Lücke in Google-Merchant-Center-Modul geschlossen #cve202685520 #gmfeed #googlemerchantcenterfeed #prestashop https://cybersecurity-news.de/prestashop-gmfeed-cve-2026-85520-rce