Vulnerabilities
Vulnerable Software
Shopxo:  >> Shopxo  >> 1.4.0  Security Vulnerabilities
A vulnerability was found in ShopXO up to 6.1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file extend/base/Uploader.php. The manipulation of the argument source leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-270367. NOTE: The original disclosure confuses CSRF with SSRF.
CVSS Score
5.5
EPSS Score
0.002
Published
2024-07-05
Incorrect Access Control in Shopxo v1.4.0 and v1.5.0 allows remote attackers to gain privileges in "/index.php" by manipulating the parameter "user_id" in the HTML request.
CVSS Score
9.8
EPSS Score
0.009
Published
2021-04-14


Contact Us

Shodan ® - All rights reserved