Database Reinstallation Flaw in ShopXO by GongfuXiang
CVE-2019-5886

9.8CRITICAL

Key Information:

Vendor

Shopxo

Status
Vendor
CVE Published:
10 January 2019

What is CVE-2019-5886?

A vulnerability in ShopXO 1.2.0 exists due to a lack of validation on the lock file during the database reinstallation process. This deficiency permits an attacker to manipulate the system by rewriting the 'database.php' file, ultimately allowing them to execute arbitrary code. Such an oversight represents a significant security risk, as it facilitates unauthorized control over the database, potentially compromising sensitive information and the overall integrity of the application.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-5886 : Database Reinstallation Flaw in ShopXO by GongfuXiang