CVE-2024-5049: Codezips E-Commerce Site editproduct.php unrestricted upload
A vulnerability, which was classified as critical, has been found in Codezips E-Commerce Site 1.0. Affected by this issue is some unknown functionality of the file admin/editproduct.php. The manipulation of the argument profilepic leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-264746 is the identifier assigned to this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch VDB-264746 - Compensating control
Mitigate the unrestricted upload in Codezips E-Commerce Site by blocking remote access to the vulnerable endpoint/file admin/editproduct.php at the network layer (e.g., restrict/deny HTTP/S access to admin/editproduct.php).
- Operational
Review and remove any files uploaded via the unrestricted upload vector (admin/editproduct.php), and clean up any webshells/malicious payloads if present.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5049?
CVE-2024-5049 is classified as a critical vulnerability.
How do I fix CVE-2024-5049?
To fix CVE-2024-5049, restrict file uploads in the admin/editproduct.php file and validate input parameters.
What products are affected by CVE-2024-5049?
CVE-2024-5049 affects Codezips E-Commerce Site version 1.0.
What is the exploitation impact of CVE-2024-5049?
CVE-2024-5049 allows for unrestricted file upload, potentially leading to remote code execution.
Who should be concerned about CVE-2024-5049?
Developers and administrators using Codezips E-Commerce Site 1.0 should be particularly concerned about CVE-2024-5049.