PT-2022-18080 · Sourcecodester · Sourcecodester Alphaware Simple E-Commerce System

Published

2022-08-05

·

Updated

2022-08-10

·

CVE-2022-2678

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions SourceCodester Alphaware Simple E-Commerce System (affected versions not specified)
Description A critical issue was discovered, affecting the Background Management Page component, specifically the admin feature.php file, allowing for unrestricted upload. This can be initiated remotely.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2022-2678

Affected Products

Sourcecodester Alphaware Simple E-Commerce System