Aller au contenu

Fiche vulnérabilité

CVE-2024-4923 : faille élevée codezips e-commerce site (CVSS 8.8)

Description

A vulnerability has been found in Codezips E-Commerce Site 1.0 and classified as critical. This vulnerability affects unknown code of the file admin/addproduct.php. The manipulation of the argument profilepic leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264460.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
16 mai 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • codezips e-commerce site

Références

Rechercher une autre vulnérabilité dans la base CVE