Impact
A security vulnerability exists in aircheng‑org iWebShop‑5 in the uploadFile function of controllers/pic.php. By manipulating the outerSrc/selectPhoto parameter, an attacker can inject scripts that are subsequently rendered in the web page. This flaw is a classic reflected or stored cross‑site scripting (XSS) vulnerability. The CVE description notes that the attack can be performed remotely and that the exploit has been publicly disclosed, but it does not specify particular consequences beyond the injected code execution on the victim’s browser.
Affected Systems
The vulnerability affects all instances of aircheng‑org iWebShop‑5 up to and including version 5.15. No other versions or related products are mentioned in the advisory. The flaw resides specifically in the file upload controller located at controllers/pic.php.
Risk and Exploitability
The CVSS base score of 5.3 indicates medium severity, and the EPSS score of less than 1% suggests a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The attack may be carried out from a remote network location without requiring authentication; the flaw does not involve local privilege escalation. The likely attack vector is remote access to the uploadFile endpoint. Overall, the risk remains moderate and the potential impact extends to any users who view the affected page after a malicious upload.
OpenCVE Enrichment