vendor:
Easy Shop
by:
Ihsan Sencan
7.5
CVSS
HIGH
Local File Inclusion
22
CWE
Product Name: Easy Shop
Affected Version From: 1.2.3
Affected Version To: 1.2.3
Patch Exists: YES
Related CWE: N/A
CPE: a:joomtech:easy_shop:1.2.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WiN7_x64/KaLiLinuX_x64
2019
Joomla! Component Easy Shop 1.2.3 – Local File Inclusion
Joomla! Component Easy Shop 1.2.3 is vulnerable to Local File Inclusion. An attacker can exploit this vulnerability to read sensitive files from the server. This vulnerability exists due to insufficient sanitization of user-supplied input to the 'file' parameter of the 'index.php' script. An attacker can send a specially crafted HTTP request to the vulnerable script and read sensitive files from the server.
Mitigation:
The vendor has released a patch to address this vulnerability. Users are advised to upgrade to the latest version of the software.