PT-2023-2087 · Ecshop · Ecshop
Oreoze
·
Published
2023-03-06
·
Updated
2024-05-17
·
CVE-2023-1185
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ECshop versions up to 4.1.8
Description
A vulnerability was found in the New Product Handler component of ECshop, allowing for unrestricted file upload. This can be exploited remotely, potentially allowing an attacker to upload arbitrary files. The exploit has been disclosed publicly.
Recommendations
For ECshop versions up to 4.1.8, update to a version later than 4.1.8 to resolve the issue. As a temporary workaround, consider restricting access to the New Product Handler component to minimize the risk of exploitation.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ecshop