File Upload Vulnerability in Niushop Multi-business Software
CVE-2020-19672
9.8CRITICAL
What is CVE-2020-19672?
A file upload vulnerability exists in the Niushop B2B2C Multi-business basic version V1.11, allowing attackers to bypass administrator controls and gain access to the backend upload interface. By manipulating parameters, an attacker can circumvent the getimagesize function, enabling the upload of malicious PHP files and potentially compromising the system through remote code execution.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
