First published: Thu Mar 21 2024(Updated: )
An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administrator profile photo upload feature.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
osCommerce Poll Booth |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22724 is considered a critical vulnerability due to its potential to allow arbitrary code execution.
To fix CVE-2024-22724, you should update to the latest version of osCommerce that addresses this vulnerability.
CVE-2024-22724 affects installations of osCommerce v4 that have not implemented proper file upload restrictions.
CVE-2024-22724 enables local attackers to bypass file upload restrictions in the administrator profile photo upload feature.
OsCommerce has acknowledged CVE-2024-22724 and is actively working on a patch to resolve the vulnerability.