EcShop PHP File template.php unrestricted upload
CVE-2023-0783
9.8CRITICAL
What is CVE-2023-0783?
A vulnerability in EcShop 4.1.5 allows for unrestricted file uploads via the PHP File Handler in the file /ecshop/admin/template.php. This issue permits remote attackers to upload malicious files, potentially compromising the integrity and security of the application. As the exploit has been publicly disclosed, it is crucial for users and administrators of EcShop to implement security measures immediately to mitigate this threat.
Affected Version(s)
EcShop 4.1.5
