PT-2023-7519 · Unknown · Semcms Shop
CVE-2023-30090
·
Publicado
2023-04-07
·
Atualizado
2023-05-11
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Semcms Shop version 4.2
Description
The issue is related to an arbitrary file upload vulnerability via the SEMCMS Upfile.php component. This allows attackers to execute arbitrary code by uploading a crafted PHP file. The vulnerability can be exploited remotely.
Recommendations
For Semcms Shop version 4.2, consider disabling the SEMCMS Upfile.php component until a patch is available to prevent arbitrary file uploads and mitigate the risk of code execution. Restrict access to the file upload functionality to minimize the risk of exploitation.
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Semcms Shop