File Upload Vulnerability in Niushop B2B2C Multi-business
CVE-2018-14570
8.8HIGH
What is CVE-2018-14570?
A vulnerability exists in the Niushop B2B2C Multi-business application that allows unauthorized file uploads through the profile avatar field. By exploiting this flaw, a remote attacker can upload a malicious .php file by using an image content type and crafting a deceptive filename. This action could lead to arbitrary code execution on the web server once the attacker accesses the uploaded file.