vendor:
Online Shopping Portal
by:
Tagoletta (Tağmaç)
9,8
CVSS
HIGH
Remote Code Execution
79
CWE
Product Name: Online Shopping Portal
Affected Version From: V3.1
Affected Version To: V3.1
Patch Exists: YES
Related CWE: N/A
CPE: a:phpgurukul:online_shopping_portal:3.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows & Ubuntu
2021
Online Shopping Portal 3.1 – Remote Code Execution (Unauthenticated)
An unauthenticated attacker can exploit a vulnerability in Online Shopping Portal 3.1 to execute arbitrary code on the server. The vulnerability exists due to insufficient validation of user-supplied input in the 'insert-product.php' script. An attacker can exploit this vulnerability by sending a specially crafted HTTP request with malicious PHP code in the 'productImage' parameter. This will allow the attacker to execute arbitrary code on the server.
Mitigation:
The vendor has released a patch to address this vulnerability. It is recommended to update the application to the latest version.