PT-2022-17917 · Unknown · Abantecart

Cyberinsane

·

Published

2022-03-07

·

Updated

2024-03-06

·

CVE-2022-26521

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Abantecart versions prior to 1.3.3
Description The issue allows remote authenticated administrators to execute arbitrary code by uploading an executable file. This is possible because the Catalog>Media Manager>Images settings can be changed by an administrator, for example, by configuring .php to be a valid image file type.
Recommendations For Abantecart versions prior to 1.3.3, update to version 1.3.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the Media Manager and limiting the types of files that can be uploaded to prevent potential exploitation.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BIT-ABANTECART-2022-26521
CVE-2022-26521

Affected Products

Abantecart