Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Qhxb

#27653of 56,330
9.8Total CVSS
Vulnerabilities · 1
PT-2021-10412
9.8
2021-04-14
Shopxo · Shopxo · CVE-2020-19778
Name of the Vulnerable Software and Affected Versions: Shopxo versions 1.4.0 through 1.5.0 Description: The issue allows remote attackers to gain privileges by manipulating the `user id` parameter in the HTML request to the "/index.php" endpoint. Recommendations: For versions 1.4.0 through 1.5.0, as a temporary workaround, consider restricting access to the "/index.php" endpoint until a patch is available. Avoid using the `user id` parameter in the affected endpoint until the issue is resolved.