Lucene search

K
osvGoogleOSV:CVE-2021-27817
HistoryMar 15, 2021 - 5:15 p.m.

CVE-2021-27817

2021-03-1517:15:22
Google
osv.dev
4
cve-2021-27817
remote command execution
shopxo 1.9.3
vulnerability
upload malicious code
phar suffix
jpg
software

AI Score

7.3

Confidence

High

EPSS

0.005

Percentile

76.4%

A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which is uploaded after modifying the phar suffix.

AI Score

7.3

Confidence

High

EPSS

0.005

Percentile

76.4%

Related for OSV:CVE-2021-27817