B
今週中
MyPresta社の「Google Merchant Center Feed」モジュールに、認証なしで任意のファイルを書き込める脆弱性(CVE-2026-855…
📌 一言でいうと
MyPresta社の「Google Merchant Center Feed」モジュールに、認証なしで任意のファイルを書き込める脆弱性(CVE-2026-85520)が発見されました。攻撃者はfeed.phpエンドポイントを通じて悪意のあるPHPファイルをアップロードし、リモートでコードを実行(RCE)させることが可能です。この問題はバージョン2.3.9で修正されています。
🔍該当判定
- ECサイト構築ソフト「PrestaShop」を利用している
- PrestaShopの拡張機能として「MyPresta Google Merchant Center Feed」を導入している
- 利用している「MyPresta Google Merchant Center Feed」のバージョンが 1.9.1 から 2.3.8 の間である
上記いずれにも該当しない → 静観でOK
✅該当時の対応
影響を受けるバージョンを利用している場合は、速やかに最新バージョン(2.3.9以降)へアップデートしてください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】MyPresta Google Merchant Center Feed CVE-2026-85520 対応について
お疲れさまです。MyPresta社のモジュールにおける脆弱性に関する情報共有です。
■ 概要
PrestaShop用モジュール「Google Merchant Center Feed」に、認証不要で任意のファイルを書き込める脆弱性が確認されました。攻撃者が悪意のあるPHPファイルをアップロードすることで、リモートコード実行(RCE)に至る恐れがあります。
■ 影響範囲
- 対象製品: MyPresta Google Merchant Center Feed
- 対象バージョン: 1.9.1 から 2.3.8 まで
■ 対応手順
1. 利用中のモジュールバージョンを確認してください。
2. 脆弱性が存在するバージョンの場合、速やかにバージョン 2.3.9 以降へアップデートを適用してください。
■ 参考情報
- CERT Polska アドバイザリ
対応優先度: 高
対応期限: 速やかに
お疲れさまです。MyPresta社のモジュールにおける脆弱性に関する情報共有です。
■ 概要
PrestaShop用モジュール「Google Merchant Center Feed」に、認証不要で任意のファイルを書き込める脆弱性が確認されました。攻撃者が悪意のあるPHPファイルをアップロードすることで、リモートコード実行(RCE)に至る恐れがあります。
■ 影響範囲
- 対象製品: MyPresta Google Merchant Center Feed
- 対象バージョン: 1.9.1 から 2.3.8 まで
■ 対応手順
1. 利用中のモジュールバージョンを確認してください。
2. 脆弱性が存在するバージョンの場合、速やかにバージョン 2.3.9 以降へアップデートを適用してください。
■ 参考情報
- CERT Polska アドバイザリ
対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] MyPresta Google Merchant Center Feed CVE-2026-85520
Dear IT/Security Team,
We are sharing information regarding a critical vulnerability in the MyPresta Google Merchant Center Feed module.
■ Overview
An unauthenticated file upload vulnerability (CVE-2026-85520) has been identified in the feed.php endpoint. This allows an attacker to upload and execute arbitrary PHP code (RCE) on the server.
■ Scope
- Product: MyPresta Google Merchant Center Feed
- Affected Versions: 1.9.1 through 2.3.8
■ Remediation
1. Verify the current version of the installed module.
2. Update the module to version 2.3.9 or later immediately.
■ Reference
- CERT Polska Advisory
Priority: High
Deadline: Immediate
Dear IT/Security Team,
We are sharing information regarding a critical vulnerability in the MyPresta Google Merchant Center Feed module.
■ Overview
An unauthenticated file upload vulnerability (CVE-2026-85520) has been identified in the feed.php endpoint. This allows an attacker to upload and execute arbitrary PHP code (RCE) on the server.
■ Scope
- Product: MyPresta Google Merchant Center Feed
- Affected Versions: 1.9.1 through 2.3.8
■ Remediation
1. Verify the current version of the installed module.
2. Update the module to version 2.3.9 or later immediately.
■ Reference
- CERT Polska Advisory
Priority: High
Deadline: Immediate