File Upload Vulnerability in Niushop Multi-business Software
CVE-2020-19672
9.8CRITICAL
What is CVE-2020-19672?
A file upload vulnerability exists in the Niushop B2B2C Multi-business basic version V1.11, allowing attackers to bypass administrator controls and gain access to the backend upload interface. By manipulating parameters, an attacker can circumvent the getimagesize function, enabling the upload of malicious PHP files and potentially compromising the system through remote code execution.