An issue was discovered in Webiness Inventory 2.3. The ProductModel component allows Arbitrary File Upload via a crafted product image during the creation of a new product. Consequently, an attacker can steal information from the site with the help of an installed executable file, or change the contents of pages.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T21:17:31.725Z
Reserved: 2019-02-17T00:00:00
Link: CVE-2019-8404
No data.
Status : Modified
Published: 2019-05-14T16:29:02.203
Modified: 2024-11-21T04:49:50.940
Link: CVE-2019-8404
No data.
OpenCVE Enrichment
No data.
Weaknesses