Impact
The vulnerability resides in the upload_json/uploadFile function of pic.php in aircheng-org iWebShop-5 and allows an attacker to upload arbitrary files without restrictions. Because the upload endpoint does not validate file type or enforce appropriate access controls, an attacker may store malicious files that later could be executed, exposing the system to remote code execution or other attacks. The flaw is present in all releases up to 5.15.
Affected Systems
The impacted product is aircheng-org iWebShop-5. All versions up to and including 5.15 are vulnerable. No other products or prior releases are affected according to the current data.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the exploit is currently publicly available. The EPSS score is not reported, but the vulnerability is not listed in the CISA KEV catalog. Attackers can reach the upload function remotely over the web, and given the lack of file type validation the risk of executing arbitrary code is high. Therefore, the vulnerability is considered a significant threat that warrants prompt remediation.
OpenCVE Enrichment