vendor:
XOS Shop System
by:
faisalfs10x
7,5
CVSS
HIGH
Arbitrary File Deletion
284
CWE
Product Name: XOS Shop System
Affected Version From: 1.0.9
Affected Version To: 1.0.9
Patch Exists: YES
Related CWE: N/A
CPE: a:xos-shop:xos_shop_system:1.0.9
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 10, XAMPP
2021
XOS Shop 1.0.9 – ‘Multiple’ Arbitrary File Deletion (Authenticated)
XOS-Shop prior to version 1.0.9 suffers from an arbitrary file deletion vulnerability in Admin Panel. Exploiting the vulnerability allows an authenticated attacker to delete any file in the web root (along with any other file on the server that the PHP process user has the proper permissions to delete). Furthermore, an attacker might leverage the capability of arbitrary file deletion to circumvent certain webserver security mechanisms such as deleting .htaccess file that would deactivate those security constraints.
Mitigation:
Ensure that the web application is running the latest version of XOS-Shop and that all security patches are applied.