File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image upload feature when customizing a shop.
The vulnerability (CWE-434 — Unrestricted Upload of File with Dangerous Type) is located in the image upload function during store appearance customization. An attacker can upload a file of dangerous type (e.g., server script) instead of a proper image. The server does not properly verify the uploaded file, which allows its subsequent execution on the server side.
An attacker can remotely execute arbitrary code on the server (RCE), which consequently may lead to complete takeover of the system, data theft, or further compromise of the infrastructure.
Patches available from the manufacturer should be applied according to the references. Additionally, it is recommended to implement restrictive verification of uploaded file types on the server side and restrict access to administrative functions to trusted IP addresses only.
CS-Cart MultiVendor version 4.16.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCs Cart Multivendor
APPCs-Cart4.16.1
Related vulnerabilities
CS-Cart MultiVendor — nieautoryzowana modyfikacja profili użytkowników przez API
File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File...
Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive in...
Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code ...
Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 ...