CVE-2022-39978
Last modified
CVE-2022-39978 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in the Product List module. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file uploaded through the picture upload point.. EPSS estimates a 1.06% chance of exploitation in the next 30 days.
Description
Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in the Product List module. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file uploaded through the picture upload point.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Online Pet Shop We App Project | Online Pet Shop We App | 1.0 |
References
- https://github.com/z1pwn/bug_report/blob/main/vendors/oretnom23/online-pet-shop-we-app/RCE-1.mdExploit, Third Party Advisory
- https://github.com/z1pwn/bug_report/blob/main/vendors/oretnom23/online-pet-shop-we-app/RCE-1.mdExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-39978?
How severe is CVE-2022-39978?
How do I fix CVE-2022-39978?
Are you affected by CVE-2022-39978?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
