PT-2024-39382 · Unknown · Codezips Online Shopping Portal

N3Xu5Cr4Ck37

·

Published

2024-09-20

·

Updated

2024-09-27

·

CVE-2024-9038

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Codezips Online Shopping Portal version 1.0
Description A vulnerability was found in the Codezips Online Shopping Portal, affecting an unknown functionality of the file insert-product.php. The manipulation of the productimage1, productimage2, and productimage3 arguments leads to unrestricted upload. The attack can be launched remotely.
Recommendations For Codezips Online Shopping Portal version 1.0, consider restricting access to the insert-product.php file to minimize the risk of exploitation. As a temporary workaround, avoid using the productimage1, productimage2, and productimage3 arguments in the affected functionality until a patch is available.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-9038

Affected Products

Codezips Online Shopping Portal