ZeroHour

CVE-2024-22724

PoC ×2
CVSS 3.1
6.6 medium
EPSS
<1%p23
Published
()
Modified
Description

An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administrator profile photo upload feature.

Vendors
oscommerce
Products
oscommerce
Weakness
CWE-94
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

In the news

No ingested article mentions this CVE yet.