First published: Fri Sep 20 2024(Updated: )
A vulnerability classified as problematic was found in Codezips Online Shopping Portal 1.0. Affected by this vulnerability is an unknown functionality of the file insert-product.php. The manipulation of the argument productimage1/productimage2/productimage3 leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Online Shopping Portal | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9038 is classified as problematic due to the risk of unrestricted file uploads.
To fix CVE-2024-9038, you should restrict file upload types and validate the file inputs in the insert-product.php file.
CVE-2024-9038 affects Codezips Online Shopping Portal version 1.0.
CVE-2024-9038 is a vulnerability that allows for unrestricted file uploads.
Yes, an attacker could exploit CVE-2024-9038 to upload malicious files to the server.