A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which is uploaded after modifying the phar suffix.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2022-5875 | A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which is uploaded after modifying the phar suffix. |
![]() |
GHSA-xx77-w6p5-xvmj | ShopXO RCE Vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T21:33:16.288Z
Reserved: 2021-03-01T00:00:00
Link: CVE-2021-27817

No data.

Status : Modified
Published: 2021-03-15T17:15:22.440
Modified: 2024-11-21T05:58:36.550
Link: CVE-2021-27817

No data.

No data.