Unrestricted Upload Vulnerability in JPShop (CVE-2023-252998)
CVE-2024-1259

9.8CRITICAL

Key Information:

Vendor

Juanpao

Status
Vendor
CVE Published:
6 February 2024

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2024-1259?

A vulnerability has been identified in the Juanpao JPShop software affecting versions up to 1.5.02. This vulnerability exists within the API component specifically in the file located at /api/controllers/admin/app/AppController.php. The issue arises from improper handling of the app_pic_url argument, which permits unrestricted file uploads. This can potentially enable attackers to upload malicious files remotely, which poses a severe risk to the integrity and security of the affected system. Given that exploit details have been made public, immediate remediation is essential to mitigate any exposure to exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

JPShop 1.5.02

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

glzjin (VulDB User)
.