PT-2022-18391 · Unknown · Ecommerce-Website

Published

2022-04-08

·

Updated

2022-04-14

·

CVE-2022-27357

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ecommerce-Website version v1
Description The issue is related to an arbitrary file upload vulnerability via the "/customer register.php" API endpoint. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Recommendations For Ecommerce-Website version v1, consider disabling the file upload functionality in the "/customer register.php" endpoint until a patch is available. Restrict access to this endpoint to minimize the risk of exploitation. Avoid using this endpoint for file uploads until the issue is resolved.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-27357

Affected Products

Ecommerce-Website