PT-2026-109731 · Innocommerce · Innoshop
CVSS v3.1
4.4
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N |
InnoShop 0.9.2 contains a local file disclosure vulnerability that allows authenticated administrators with files create permission to read server files by abusing the AI Core MCP file upload tool's source argument. Attackers can supply file:// or php:// stream wrappers passed to file get contents(), storing contents on the public media disk to expose the .env file with APP KEY and database credentials.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Innoshop