Arbitrary File Deletion Vulnerability in ECShop by ECShop
CVE-2023-39112

6.5MEDIUM

Key Information:

Vendor

Shopex

Status
Vendor
CVE Published:
4 August 2023

What is CVE-2023-39112?

ECShop version 4.1.16 is susceptible to an arbitrary file deletion vulnerability via its Admin Panel. This flaw allows attackers to delete files without proper authorization, potentially leading to service disruption and data loss. Administrators should apply security patches promptly to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.