vendor:
ShopNx
by:
L0RD
8.8
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: ShopNx
Affected Version From: 1
Affected Version To: 1
Patch Exists: YES
Related CWE: CVE-2018-12519
CPE: a:codenx:shopnx:1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Win 10
2018
ShopNx – Angular5 Single Page Shopping Cart Application 1 – Arbitrary File Upload
ShopNx 1 is an Angular 5 single page application which suffers from arbitrary file upload vulnerability. Attacker can upload malicious files on server because the application fails to sufficiently sanitize user-supplied input.
Mitigation:
The application should properly sanitize user-supplied input to prevent malicious files from being uploaded.