PT-2019-17845 · Shopxo · Shopxo

Qianxincodesafe

·

Published

2019-01-10

·

Updated

2019-01-18

·

CVE-2019-5887

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions ShopXO version 1.2.0
Description An issue in the UnlinkDir method of the FileUtil.php file allows input mishandling by the rmdir method due to unchecked input parameters. This enables attackers to delete arbitrary files using "../" directory traversal.
Recommendations For ShopXO version 1.2.0, consider implementing input validation in the UnlinkDir method of the FileUtil.php file to prevent directory traversal attacks. As a temporary workaround, restrict access to the UnlinkDir method to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-5887

Affected Products

Shopxo