First published: Mon Mar 07 2022(Updated: )
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Catalog>Media Manager>Images settings can be changed by an administrator (e.g., by configuring .php to be a valid image file type).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Abantecart | <=1.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-26521 has a high severity rating due to its potential for remote code execution by authenticated administrators.
To fix CVE-2022-26521, ensure that the file upload settings do not allow executable file types such as .php to be uploaded via the media manager.
CVE-2022-26521 affects Abantecart versions up to and including 1.3.2 for installations that allow file uploads by authenticated administrators.
CVE-2022-26521 is associated with remote code execution attacks due to improper handling of file uploads.
No, CVE-2022-26521 requires authenticated administrative access to exploit the vulnerability.