ECshop New Product unrestricted upload
CVE-2023-1185

8.8HIGH

Key Information:

Vendor

Shopex

Status
Vendor
CVE Published:
6 March 2023

What is CVE-2023-1185?

A security vulnerability has been discovered in ECshop versions prior to 4.1.8, manifesting in the New Product Handler component. This flaw allows for unrestricted file uploads, which can be exploited remotely. Given the public disclosure of this vulnerability, it poses a significant risk to users, potentially enabling attackers to upload malicious files to the server.

Affected Version(s)

ECshop 4.1.0

ECshop 4.1.1

ECshop 4.1.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

OreoZe (VulDB User)
.