CVE-2023-0783: EcShop PHP File template.php unrestricted upload
A vulnerability was found in EcShop 4.1.5. It has been classified as critical. This affects an unknown part of the file /ecshop/admin/template.php of the component PHP File Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-220641 was assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0783?
The severity of CVE-2023-0783 is critical with a severity value of 9.8.
What is the affected software for CVE-2023-0783?
The affected software for CVE-2023-0783 is EcShop 4.1.5.
How does CVE-2023-0783 affect EcShop?
CVE-2023-0783 affects EcShop by allowing unrestricted upload via the template.php file.
Is CVE-2023-0783 remotely exploitable?
Yes, CVE-2023-0783 can be initiated remotely.
Is there a fix available for CVE-2023-0783?
There is no information available regarding a fix for CVE-2023-0783. It is recommended to follow the recommendations from the vendor or security advisories.