ZeroHour

CVE-2024-50648

PoC ×2
CVSS 3.1
9.8 critical
EPSS
1%p61
Published
()
Modified
Description

yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.

Vendors
guchengwuyue
Products
yshopmall
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.