CRITICAL🇵🇱 Wersja polska

CVE-2023-26686

CVSS 9.8v3.1pub. 2024-09-25upd. 2025-04-24

File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image upload feature when customizing a shop.

🤖 AI Analysis
How it works

The vulnerability (CWE-434 — Unrestricted Upload of File with Dangerous Type) is located in the image upload function during store appearance customization. An attacker can upload a file of dangerous type (e.g., server script) instead of a proper image. The server does not properly verify the uploaded file, which allows its subsequent execution on the server side.

Impact

An attacker can remotely execute arbitrary code on the server (RCE), which consequently may lead to complete takeover of the system, data theft, or further compromise of the infrastructure.

Mitigation & patch

Patches available from the manufacturer should be applied according to the references. Additionally, it is recommended to implement restrictive verification of uploaded file types on the server side and restrict access to administrative functions to trusted IP addresses only.

Who is affected

CS-Cart MultiVendor version 4.16.1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Cs Cart Multivendor

    APP
    Cs-Cart
    4.16.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-26689CRITICAL9.8PL ✓same product

CS-Cart MultiVendor — nieautoryzowana modyfikacja profili użytkowników przez API

CVE-2023-26690HIGH8.8same product

File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File...

CVE-2023-26687HIGH8.8same product

Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive in...

CVE-2023-26691HIGH7.2same product

Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code ...

CVE-2017-2138HIGH8.8same product

Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 ...