PT-2024-18238 · Shopwind · Shopwind

Glzjin

·

Published

2024-02-21

·

Updated

2024-05-17

·

CVE-2024-1705

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Shopwind versions up to 4.6
Description A critical issue affects the actionCreate function of the /public/install/controllers/DefaultController.php file in the Installation component, leading to code injection. The attack can be initiated remotely, but the complexity is rather high, making exploitation difficult.
Recommendations For Shopwind versions up to 4.6, consider disabling the actionCreate function of the /public/install/controllers/DefaultController.php file as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-1705

Affected Products

Shopwind