PT-2024-39382 · Unknown · Codezips Online Shopping Portal

·

CVE-2024-9038

·

Published

2024-09-20

·

Updated

2024-09-27

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Codezips Online Shopping Portal version 1.0
Description A vulnerability was found in the Codezips Online Shopping Portal, affecting an unknown functionality of the file insert-product.php. The manipulation of the productimage1, productimage2, and productimage3 arguments leads to unrestricted upload. The attack can be launched remotely.
Recommendations For Codezips Online Shopping Portal version 1.0, consider restricting access to the insert-product.php file to minimize the risk of exploitation. As a temporary workaround, avoid using the productimage1, productimage2, and productimage3 arguments in the affected functionality until a patch is available.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-9038

Affected Products

Codezips Online Shopping Portal