vendor:
LiteCart
by:
Haboob Team
8.8
CVSS
HIGH
Arbitrary File Upload
CWE
Product Name: LiteCart
Affected Version From: 2.1.2002
Affected Version To: 2.1.2002
Patch Exists: YES
Related CWE: CVE-2018-12256
CPE:
Platforms Tested:
2018
LiteCart 2.1.2 – Arbitrary File Upload
admin/vqmods.app/vqmods.inc.php in LiteCart 2.1.2 allows remote authenticated attackers to upload a malicious file (resulting in remote code execution) by using the text/xml or application/xml Content-Type in a public_html/admin/?app=vqmods&doc=vqmods request.
Mitigation:
Apply the vendor provided patch or upgrade to a newer version.