A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which is uploaded after modifying the phar suffix.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5875 | A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which is uploaded after modifying the phar suffix. |
Github GHSA |
GHSA-xx77-w6p5-xvmj | ShopXO RCE Vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T21:33:16.288Z
Reserved: 2021-03-01T00:00:00
Link: CVE-2021-27817
No data.
Status : Modified
Published: 2021-03-15T17:15:22.440
Modified: 2024-11-21T05:58:36.550
Link: CVE-2021-27817
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA