yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.
History

Tue, 03 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Yshopmall
Yshopmall yshopmall
Weaknesses CWE-22
CPEs cpe:2.3:a:yshopmall:yshopmall:*:*:*:*:*:*:*:*
Vendors & Products Yshopmall
Yshopmall yshopmall
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 15 Nov 2024 16:00:00 +0000

Type Values Removed Values Added
Description yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-11-15T00:00:00

Updated: 2024-12-03T16:35:37.378Z

Reserved: 2024-10-28T00:00:00

Link: CVE-2024-50648

cve-icon Vulnrichment

Updated: 2024-12-03T16:35:32.061Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-15T16:15:36.547

Modified: 2024-12-03T17:15:11.357

Link: CVE-2024-50648

cve-icon Redhat

No data.