PT-2026-109731 · Innocommerce · Innoshop
CVSS v3.1
4.4
Média
| Vetor | AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N |
InnoShop 0.9.2 contains a local file disclosure vulnerability that allows authenticated administrators with files create permission to read server files by abusing the AI Core MCP file upload tool's source argument. Attackers can supply file:// or php:// stream wrappers passed to file get contents(), storing contents on the public media disk to expose the .env file with APP KEY and database credentials.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Innoshop