First published: Mon Mar 06 2023(Updated: )
A vulnerability, which was classified as problematic, has been found in ECshop up to 4.1.8. Affected by this issue is some unknown functionality of the file admin/database.php of the component Backup Database Handler. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-222356.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Shopex Ecshop | <=4.1.8 | |
<=4.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this ECshop vulnerability is CVE-2023-1184.
The severity of CVE-2023-1184 is high with a severity value of 8.8.
The affected software of CVE-2023-1184 is ECshop up to 4.1.8.
The CWE category of CVE-2023-1184 is CWE-434.
To fix the ECshop Backup Database database.php unrestricted upload vulnerability, you should update ECshop to a version higher than 4.1.8 as soon as a patch becomes available.