First published: Fri Jul 05 2024(Updated: )
A vulnerability was found in ShopXO up to 6.1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file `extend/base/Uploader.php`. The manipulation of the argument source leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-270367. NOTE: The original disclosure confuses CSRF with SSRF.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/shopxo/shopxo | <=6.1.0 | |
Suche Shopxs | <=6.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6524 has been declared a critical vulnerability.
CVE-2024-6524 allows for server-side request forgery through manipulation of the source argument in the file extend/base/Uploader.php.
To fix CVE-2024-6524, upgrade ShopXO to a version above 6.1.0, as this vulnerability affects versions up to and including 6.1.0.
CVE-2024-6524 affects all versions of ShopXO up to and including 6.1.0.
CVE-2024-6524 is associated with a server-side request forgery attack.