Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2xhq-4fmf-r8g2

Опубликовано: 07 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

A vulnerability, which was classified as critical, has been found in Juanpao JPShop up to 1.5.02. This issue affects the function actionUpdate of the file /api/controllers/merchant/design/MaterialController.php of the component API. The manipulation of the argument pic_url leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-253001 was assigned to this vulnerability.

A vulnerability, which was classified as critical, has been found in Juanpao JPShop up to 1.5.02. This issue affects the function actionUpdate of the file /api/controllers/merchant/design/MaterialController.php of the component API. The manipulation of the argument pic_url leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-253001 was assigned to this vulnerability.

EPSS

Процентиль: 23%
0.00077
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 6.3
nvd
около 2 лет назад

A vulnerability, which was classified as critical, has been found in Juanpao JPShop up to 1.5.02. This issue affects the function actionUpdate of the file /api/controllers/merchant/design/MaterialController.php of the component API. The manipulation of the argument pic_url leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-253001 was assigned to this vulnerability.

EPSS

Процентиль: 23%
0.00077
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-434