First published: Mon Mar 06 2023(Updated: )
A vulnerability, which was classified as problematic, was found in ECshop up to 4.1.8. This affects an unknown part of the component New Product Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-222357 was assigned to this vulnerability.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Shopex Ecshop | <=4.1.8 | |
<=4.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-1185 is high, with a severity value of 8.8.
The affected software of CVE-2023-1185 is ECshop up to version 4.1.8.
CVE-2023-1185 is a vulnerability in ECshop that allows for unrestricted file upload, potentially leading to remote code execution.
The CVE-2023-1185 vulnerability can be exploited remotely to initiate an unrestricted file upload attack.
Yes, there are references available for CVE-2023-1185: [link1](https://vuldb.com/?id.222357), [link2](https://vuldb.com/?ctiid.222357), [link3](https://github.com/wjzdalao/ecshop4.1.8/issues/2).