PT-2019-10127 · Php Scripts Mall · Php Scripts Mall Website Seller Script
Published
2019-03-20
·
Updated
2019-03-25
·
CVE-2018-20631
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
PHP Scripts Mall Website Seller Script version 2.0.5
Description:
The issue allows for full Path Disclosure via a request for an arbitrary image URL, such as a .png file.
Recommendations:
For version 2.0.5, update to a newer version that contains a fix for this issue, if available. As a temporary workaround, consider restricting access to arbitrary image URLs to minimize the risk of exploitation.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Php Scripts Mall Website Seller Script