First published: Fri Jan 26 2024(Updated: )
An arbitrary file upload vulnerability in the component /alsdemo/ss/mediam.cgi of ShopSite v14.0 allows attackers to execute arbitrary code via uploading a crafted SVG file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ShopSite | =14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22550 is considered a critical vulnerability due to its potential for arbitrary code execution.
To fix CVE-2024-22550, upgrade to a patched version of ShopSite that addresses this arbitrary file upload vulnerability.
CVE-2024-22550 can be exploited by uploading specially crafted SVG files.
CVE-2024-22550 affects ShopSite version 14.0.
Exploiting CVE-2024-22550 can allow attackers to execute arbitrary code on the server, leading to potential data breaches and system compromise.