Description
A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the file controllers/pic.php. Such manipulation of the argument outerSrc/selectPhoto leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

A security vulnerability exists in aircheng‑org iWebShop‑5 in the uploadFile function of controllers/pic.php. By manipulating the outerSrc/selectPhoto parameter, an attacker can inject scripts that are subsequently rendered in the web page. This flaw is a classic reflected or stored cross‑site scripting (XSS) vulnerability. The CVE description notes that the attack can be performed remotely and that the exploit has been publicly disclosed, but it does not specify particular consequences beyond the injected code execution on the victim’s browser.

Affected Systems

The vulnerability affects all instances of aircheng‑org iWebShop‑5 up to and including version 5.15. No other versions or related products are mentioned in the advisory. The flaw resides specifically in the file upload controller located at controllers/pic.php.

Risk and Exploitability

The CVSS base score of 5.3 indicates medium severity, and the EPSS score of less than 1% suggests a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The attack may be carried out from a remote network location without requiring authentication; the flaw does not involve local privilege escalation. The likely attack vector is remote access to the uploadFile endpoint. Overall, the risk remains moderate and the potential impact extends to any users who view the affected page after a malicious upload.

Generated by OpenCVE AI on September 10, 2026 at 03:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor patch or upgrade to a newer release once it is available.
  • Restrict the uploadFile endpoint to accept only valid image MIME types and extensions, and sanitize the outerSrc/selectPhoto input before rendering it on the page.
  • Implement a strict Content‑Security‑Policy header on all responses served by the application to reduce the effect of injected scripts.
  • If a patch is not yet released, temporarily disable or remove the ability to upload and embed external files until a fix is provided.

Generated by OpenCVE AI on September 10, 2026 at 03:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the file controllers/pic.php. Such manipulation of the argument outerSrc/selectPhoto leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title aircheng-org iWebShop-5 pic.php uploadFile cross site scripting
First Time appeared Aircheng-org
Aircheng-org iwebshop-5
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:aircheng-org:iwebshop-5:*:*:*:*:*:*:*:*
Vendors & Products Aircheng-org
Aircheng-org iwebshop-5
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Aircheng-org Iwebshop-5
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-11T20:34:25.231Z

Reserved: 2026-09-08T09:30:44.939Z

Link: CVE-2026-86668

cve-icon Vulnrichment

Updated: 2026-09-11T20:02:48.203Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T17:18:40.210

Modified: 2026-09-11T21:17:47.733

Link: CVE-2026-86668

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T08:00:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')