First published: Mon May 02 2022(Updated: )
ShopXO v2.2.5 and below was discovered to contain a system re-install vulnerability via the Add function in app/install/controller/Index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Suche Shopxs | =2.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of ShopXO is CVE-2022-28056.
The severity of CVE-2022-28056 in ShopXO v2.2.5 and below is critical, with a severity value of 9.8.
An attacker can exploit CVE-2022-28056 in ShopXO by using the Add function in app/install/controller/Index.php to carry out a system re-install vulnerability.
ShopXO v2.2.5 and below is affected by CVE-2022-28056.
It is recommended to update to a version of ShopXO that is not affected by CVE-2022-28056 to mitigate the vulnerability.