Lucene search

K
githubGitHub Advisory DatabaseGHSA-CR7J-RWMV-VGCH
HistoryJun 07, 2024 - 9:31 p.m.

Duplicate Advisory: aimeos-core arbitrary file upload vulnerability

2024-06-0721:31:54
CWE-434
GitHub Advisory Database
github.com
2
aimeos-core
vulnerability
file upload
code execution
php
image upload

7.3 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-rhc2-23c2-ww7c. This link is maintained to preserve external references.

Original Description

An arbitrary file upload vulnerability in the image upload function of aimeos-core v2024.04 allows attackers to execute arbitrary code via uploading a crafted PHP file.

Affected configurations

Vulners
Node
aimeosaimeos-coreRange<2024.04.5
CPENameOperatorVersion
aimeos/aimeos-corelt2024.04.5

7.3 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%

Related for GHSA-CR7J-RWMV-VGCH