PT-2023-2087 · Ecshop · Ecshop

Oreoze

·

Publicado

2023-03-06

·

Atualizado

2024-05-17

·

CVE-2023-1185

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ECshop versions up to 4.1.8
Description A vulnerability was found in the New Product Handler component of ECshop, allowing for unrestricted file upload. This can be exploited remotely, potentially allowing an attacker to upload arbitrary files. The exploit has been disclosed publicly.
Recommendations For ECshop versions up to 4.1.8, update to a version later than 4.1.8 to resolve the issue. As a temporary workaround, consider restricting access to the New Product Handler component to minimize the risk of exploitation.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-01820
CVE-2023-1185

Produtos afetados

Ecshop