PT-2024-15535 · Deshang · Deshang Dsshop

Glzjin

·

Published

2024-01-11

·

Updated

2024-05-17

·

CVE-2024-0412

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DeShang DSShop versions up to 3.1.0
Description A vulnerability was found in the HTTP GET Request Handler component, specifically affecting the file public/install.php. This issue leads to improper access controls and can be initiated remotely. The exploit has been disclosed to the public and may be used.
Recommendations For DeShang DSShop versions up to 3.1.0, consider restricting access to the public/install.php file until a patch is available. As a temporary workaround, disabling the HTTP GET Request Handler component may help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-0412

Affected Products

Deshang Dsshop