CVE-2026-85520 — PrestaShop gmfeed (MyPresta) Unauthenticated Arbitrary File Write → RCE
September 29, 2026 · 564 views
Google Merchant Center Feed (gmfeed) for PrestaShop ≤2.3.9: unauthenticated arbitrary file write on modules/gmfeed/feed.php when Save-to-file / URL export is enabled — attacker controls filename, path, extension, and body → PHP webshell → RCE. CVSS 9.3 Critical. Fixed in 2.3.10+ (2.4.1+ recommended). Python PoC: check, aggressive probe, exploit with marker stub, mass --list -j.
Description
Overview
CVE-2026-85520 affects MyPresta.eu / VEKIA Google Merchant Center Feed (gmfeed) for PrestaShop — module ≤ 2.3.9. CVSS 3.1 9.3 (Critical).
| | |
|---|---|
| Module | gmfeed (Google Merchant Center Feed) |
| Endpoint | modules/gmfeed/feed.php (and front controller route) |
| Auth | None on vulnerable save-to-disk export URLs |
| Impact | Arbitrary file write → RCE |
| Vendor fix | ≥ 2.3.10 (per-shop secret on save URLs); 2.4.1+ clean install recommended |
When catalog export uses “Save to file” / cron URL mode, legacy builds accepted crafted parameters controlling output filename, path, extension, and content without authentication. Attacker writes e.g. pocbit_*.php and executes it over HTTP.
PoC page: https://pocbit.org/pocs/cve-2026-85520
GitHub: murrez/CVE-2026-85520
Bundled tool (Python 3)
Download poc.py from this page (View exploit code).
pip install requests urllib3
python poc.py --lab
python poc.py -u https://shop.example.com --mode check
python poc.py -u https://shop.example.com --mode check --aggressive
python poc.py -u https://shop.example.com --mode exploit --dry-run
python poc.py -u https://shop.example.com --mode exploit
python poc.py --list targets.example.txt --mode check -j 40
python poc.py --list hits.txt --mode exploit -j 20
| Mode | Behavior |
|------|----------|
| check | Detect gmfeed (feed.php, config.xml), parse version, flag < 2.3.10 |
| check --aggressive | Lightweight save-to-file probe (no permanent shell) |
| exploit | Write pocbit_*.php marker POCBIT-85520-OK, verify ?pocbit=1 |
| mass | --list + -j → JSONL, hits.txt, exploited.txt |
Routes probed include /modules/gmfeed/feed.php and /index.php?fc=module&module=gmfeed&controller=feed.
Detection hints
body="/modules/gmfeed/" || body="gmfeed"
/modules/gmfeed/config.xml
Many shops are already ≥ 2.3.10 after vendor advisories — expect patched_version on wide scans.
Remediation
- Uninstall gmfeed with delete module files (removes vulnerable
feed.php). - Install gmfeed 2.4.1+ (minimum 2.3.10) from MyPresta.
- Regenerate all “Save to file” / cron URLs from Back Office (new store key).
- Audit
modules/gmfeed/for unexpected.phpfiles.
Legal and ethical use
Authorized security testing and patch validation only.
References
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- Web appCVE-2026-90817critical
CVE-2026-90817 — REDCap Unauthenticated RCE (Survey __passthru / Data Import)
Unauthenticated remote code execution in REDCap ≥ 13.3.0 via public survey __passthru routing and Data Import path handling. Patched in 16.0.49, 17.3.10, and 17.4.4+. Requires a valid public survey hash (s=) for the published check/exploit tooling.
- JoomlaCVE-2026-102427critical
CVE-2026-102427 — OrdaSoft Joomla CCK (com_os_cck) Unauthenticated Upload RCE
OrdaSoft OS CCK for Joomla 1.0.0–8.3.15: unauthenticated front-end task getContent reaches site/uploader.php — GIF/PHP polyglot passes magic-byte check while .php extension from attacker filename is written under web root (CWE-434). CVSS 4.0 10.0 Critical (AT:N). Fixed in 8.3.16+. Python PoC: check, exploit (POCBIT-102427-OK), mass + interactive.
- Web appCVE-2026-82384critical
CVE-2026-82384 — Apache Roller 6.1.5 XML-RPC Pre-Auth Java Deserialization
Unauthenticated Java deserialization (CWE-502) on Apache Roller 6.1.5 legacy XML-RPC servlet: enabledForExtensions allows ex:serializable before Blogger/MetaWeblog auth; mapping stays active even when XML-RPC is disabled in UI. Pre-auth RCE via attacker-controlled serialized objects (ysoserial/classpath gadgets). Fixed in 6.1.6+. CVSS 9.8 Critical. Python PoC: check, probe-deser, exploit, mass -j.
- JoomlaCVE-2026-102425critical
CVE-2026-102425 — Joomla Balbooa Forms (com_baforms) Field Shortcode → Unauthenticated RCE
Balbooa Forms for Joomla 1.0.0–2.4.3.3: when a public form runs PHP-after-submission via eval(), field shortcodes are replaced with raw visitor input inside double-quoted PHP — classic ";breakout;// → RCE. CVSS 4.0 9.5 Critical (AT:P). Fixed in 2.4.3.4. Not CVE-2026-67364. Python PoC: version + public form detect, check/exploit, up.php drop, interactive + mass -j.