PT-2026-87169 · Aircheng Org · Iwebshop-5

·

CVE-2026-86666

·

Publicado

2026-09-08

·

Atualizado

2026-09-08

CVSS v3.1

7.3

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
A security flaw has been discovered in aircheng-org iWebShop-5 up to 5.15. Impacted is the function upload json/uploadFile of the file controllers/pic.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Exploit

Correção

Improper Access Control

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-86666

Produtos afetados

Iwebshop-5