Description
A security flaw has been discovered in aircheng-org iWebShop-5 up to 5.15. Impacted is the function upload_json/uploadFile of the file controllers/pic.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-08
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the upload_json/uploadFile function of pic.php in aircheng-org iWebShop-5 and allows an attacker to upload arbitrary files without restrictions. Because the upload endpoint does not validate file type or enforce appropriate access controls, an attacker may store malicious files that later could be executed, exposing the system to remote code execution or other attacks. The flaw is present in all releases up to 5.15.

Affected Systems

The impacted product is aircheng-org iWebShop-5. All versions up to and including 5.15 are vulnerable. No other products or prior releases are affected according to the current data.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, and the exploit is currently publicly available. The EPSS score is not reported, but the vulnerability is not listed in the CISA KEV catalog. Attackers can reach the upload function remotely over the web, and given the lack of file type validation the risk of executing arbitrary code is high. Therefore, the vulnerability is considered a significant threat that warrants prompt remediation.

Generated by OpenCVE AI on September 8, 2026 at 18:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch or upgrade iWebShop-5 beyond version 5.15.
  • If an immediate upgrade is not possible, restrict the pic.php uploadFile endpoint to allow only specific image file extensions and validate MIME types.
  • Configure the web server to store uploaded files outside the web‑root and enforce non‑executable file permissions.

Generated by OpenCVE AI on September 8, 2026 at 18:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in aircheng-org iWebShop-5 up to 5.15. Impacted is the function upload_json/uploadFile of the file controllers/pic.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Title aircheng-org iWebShop-5 pic.php uploadFile unrestricted upload
First Time appeared Aircheng-org
Aircheng-org iwebshop-5
Weaknesses CWE-284
CWE-434
CPEs cpe:2.3:a:aircheng-org:iwebshop-5:*:*:*:*:*:*:*:*
Vendors & Products Aircheng-org
Aircheng-org iwebshop-5
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Aircheng-org Iwebshop-5
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-10T13:58:12.909Z

Reserved: 2026-09-08T09:30:36.740Z

Link: CVE-2026-86666

cve-icon Vulnrichment

Updated: 2026-09-10T13:57:49.990Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T16:18:31.020

Modified: 2026-09-10T14:17:09.520

Link: CVE-2026-86666

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:45:05Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-434

    Unrestricted Upload of File with Dangerous Type