Remote Command Execution Vulnerability in ShopXO by Gongfuxiang
CVE-2021-27817

9.8CRITICAL

Key Information:

Vendor

Shopxo

Status
Vendor
CVE Published:
15 March 2021

What is CVE-2021-27817?

A remote command execution vulnerability exists in ShopXO version 1.9.3, allowing attackers to exploit the system by uploading manipulated PHP Archive (phar) files with a JPG suffix. This facilitates the execution of arbitrary code, posing significant security risks to the application and its users. Proper validation of file uploads and adherence to secure coding practices are crucial to mitigate this threat.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.