ZeroHour

CVE-2021-27817

CVSS 3.1
9.8 critical
EPSS
3%p87
Published
()
Modified
Description

A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which is uploaded after modifying the phar suffix.

Vendors
shopxo
Products
shopxo
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.