vendor:
Abantecart
by:
Sarang Tumne @CyberInsane
7.2
CVSS
HIGH
Authenticated Remote Code Execution
78
CWE
Product Name: Abantecart
Affected Version From: 1.3.2002
Affected Version To: 1.3.2002
Patch Exists: NO
Related CWE: CVE-2022-26521
CPE: a:abantecart:abantecart:1.3.2
Platforms Tested:
2022
Abantecart v1.3.2 – Authenticated Remote Code Execution
Abantecart v1.3.2 is vulnerable to authenticated remote code execution. An attacker can abuse the functionality of the Media Manager to upload a malicious PHP web shell and execute it in the browser. This will give the attacker a reverse shell with the privileges of the daemon user.
Mitigation:
Disable the upload of PHP files in the Media Manager. Ensure that the web server is configured to only serve files with the appropriate MIME type.