An issue was discovered in JABA XPress Online Shop through 2018-09-14. It contains an arbitrary file upload vulnerability in the picture-upload feature of ProductEdit.aspx. An authenticated attacker may bypass the frontend filename validation and upload an arbitrary file via FileUploader.aspx.cs in FileUploader.aspx by using empty w and h parameters. This file may contain arbitrary aspx code that may be executed by accessing /Jec/ProductImages/<number>/<filename>. Accessing the file once uploaded does not require authentication.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
http://cyber-crime.ru/cve/CVE-2018-17058.html |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-03-02T13:32:47
Updated: 2024-08-05T10:39:59.203Z
Reserved: 2018-09-14T00:00:00
Link: CVE-2018-17058
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-03-02T14:15:10.917
Modified: 2024-11-21T03:53:47.640
Link: CVE-2018-17058
Redhat
No data.