← voltar
CVE-2023-27640highexploração observadaCWE-22

CVE-2023-27640

58Vexday Risk Score

Corrija agora. Ela exploração observada pelo VulnCheck e tem exploit funcional público.

ssvc Actcvss 7.5epss 3.6%
da publicação à arma
Publicada no NVD1 de jun.
VulnCheck1 de jun.
probabilidade de exploração
3.6%top 11% das CVEs
exploração observada
simVulnCheck
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the POST parameter type in the /tshirtecommerce/fonts.php endpoint, to allow a remote attacker to traverse directories on the system in order to open files (without restriction on the extension and path). The content of the file is returned with base64 encoding. This is exploited in the wild in March 2023.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Produtos afetados
n/a · n/a