Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mfr6-f95c-8chr

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An issue was discovered in ShopXO 1.2.0. In the application\install\controller\Index.php file, there is no validation lock file in the Add method, which allows an attacker to reinstall the database. The attacker can write arbitrary code to database.php during system reinstallation.

An issue was discovered in ShopXO 1.2.0. In the application\install\controller\Index.php file, there is no validation lock file in the Add method, which allows an attacker to reinstall the database. The attacker can write arbitrary code to database.php during system reinstallation.

EPSS

Процентиль: 61%
0.00407
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-667

Связанные уязвимости

CVSS3: 9.8
nvd
около 7 лет назад

An issue was discovered in ShopXO 1.2.0. In the application\install\controller\Index.php file, there is no validation lock file in the Add method, which allows an attacker to reinstall the database. The attacker can write arbitrary code to database.php during system reinstallation.

EPSS

Процентиль: 61%
0.00407
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-667