PT-2021-17629 · Shopxo · Shopxo

Published

2021-03-15

·

Updated

2022-05-24

·

CVE-2021-27817

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: shopxo version 1.9.3
Description: A remote command execution issue allows an attacker to upload malicious code generated by phar where the suffix is JPG. This is achieved by modifying the phar suffix, enabling the upload of malicious code.
Recommendations: For shopxo version 1.9.3, consider restricting the upload of files with modified suffixes to prevent exploitation until a patch is available. As a temporary workaround, restrict access to the file upload functionality to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-27817
GHSA-XX77-W6P5-XVMJ

Affected Products

Shopxo