Database Reinstallation Flaw in ShopXO by GongfuXiang
CVE-2019-5886
9.8CRITICAL
What is CVE-2019-5886?
A vulnerability in ShopXO 1.2.0 exists due to a lack of validation on the lock file during the database reinstallation process. This deficiency permits an attacker to manipulate the system by rewriting the 'database.php' file, ultimately allowing them to execute arbitrary code. Such an oversight represents a significant security risk, as it facilitates unauthorized control over the database, potentially compromising sensitive information and the overall integrity of the application.