CVE-2021-41938

HIGH7.2EPSS 0.38%

Arbitrary file upload in ShopXO

Published: 5/20/2022Modified: 11/8/2023
Also known as:GHSA-86p5-97jr-r598

Description

An issue was discovered in ShopXO CMS 2.2.0. After entering the management page, there is an arbitrary file upload vulnerability in three locations.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

References (3)