PT-2024-37689 · Shopxo · Shopxo

J1Rry

·

Published

2024-07-05

·

Updated

2024-07-08

·

CVE-2024-6524

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ShopXO versions up to 6.1.0
Description A critical vulnerability was found in ShopXO, affecting an unknown functionality of the file extend/base/Uploader.php. The manipulation of the source argument leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Recommendations For ShopXO versions up to 6.1.0, consider disabling the extend/base/Uploader.php file or restricting access to it until a patch is available. As a temporary workaround, avoid using the source argument in the affected functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-6524
GHSA-C96R-38GV-GRP4

Affected Products

Shopxo