ZeroHour

CVE-2019-8404

PoC ×2
CVSS 3.0
6.5 medium
EPSS
8%p94
Published
()
Modified
Description

An issue was discovered in Webiness Inventory 2.3. The ProductModel component allows Arbitrary File Upload via a crafted product image during the creation of a new product. Consequently, an attacker can steal information from the site with the help of an installed executable file, or change the contents of pages.

Vendors
webiness inventory project
Products
webiness inventory
Weakness
CWE-434
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.