An unrestricted file upload vulnerability was discovered in catalog/productinfo/imageupload in Fecshop FecMall 2.3.4. An attacker can bypass a front-end restriction and upload PHP code to the webserver, by providing image data and the image/jpeg content type, with a .php extension. This occurs because the code relies on the getimagesize function.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-10-04T21:55:46

Updated: 2024-08-05T01:33:17.231Z

Reserved: 2019-10-04T00:00:00

Link: CVE-2019-17188

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-10-04T22:15:11.270

Modified: 2019-10-10T19:15:06.607

Link: CVE-2019-17188

cve-icon Redhat

No data.