PT-2021-17629 · Shopxo · Shopxo
Published
2021-03-15
·
Updated
2022-05-24
·
CVE-2021-27817
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
shopxo version 1.9.3
Description:
A remote command execution issue allows an attacker to upload malicious code generated by phar where the suffix is JPG. This is achieved by modifying the phar suffix, enabling the upload of malicious code.
Recommendations:
For shopxo version 1.9.3, consider restricting the upload of files with modified suffixes to prevent exploitation until a patch is available. As a temporary workaround, restrict access to the file upload functionality to minimize the risk of exploitation.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shopxo