First published: Sat Feb 11 2023(Updated: )
A vulnerability was found in EcShop 4.1.5. It has been classified as critical. This affects an unknown part of the file /ecshop/admin/template.php of the component PHP File Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-220641 was assigned to this vulnerability.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Shopex Ecshop | =4.1.5 | |
=4.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-0783 is critical with a severity value of 9.8.
The affected software for CVE-2023-0783 is EcShop 4.1.5.
CVE-2023-0783 affects EcShop by allowing unrestricted upload via the template.php file.
Yes, CVE-2023-0783 can be initiated remotely.
There is no information available regarding a fix for CVE-2023-0783. It is recommended to follow the recommendations from the vendor or security advisories.