CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2021-27817

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1000%
EPSS Percentile9.69th
Published2021年3月15日
Last Modified2024年11月21日

Vulnerability Description

A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which is uploaded after modifying the phar suffix.

Affected Platforms (CPE)

📦
Shopxo

Shopxo

= 1.9.3

References & Advisories

相關漏洞威脅