ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php.
The vulnerability results from insufficient validation of types and content of uploaded files in the ThemeDataService.php component responsible for theme handling. An attacker can upload a file of dangerous type (e.g., PHP script) without needing permissions or user interaction. Once the malicious file is placed on the server, it can be executed remotely in the context of the web application.
Successful exploitation of this vulnerability allows an attacker to execute code remotely (RCE) on the server, which may lead to complete takeover of the application, data theft, and violation of system integrity and availability.
Apply patches available from the vendor according to the references. Temporarily, it is recommended to restrict access to file upload functionality at the firewall or web server level and monitor application directories for unauthorized files.
ShopXO version 6.4.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HShopxo
APPShopxo6.4.0
Related vulnerabilities
ShopXO – podatność umożliwiająca ponowną instalację systemu (RCE)
Nieprawidłowa kontrola dostępu w Shopxo — eskalacja uprawnień przez manipulację parametrem user_id
RCE w Shopxo 1.9.3 poprzez upload złośliwego pliku PHAR z fałszywym rozszerzeniem JPG
ShopXO – brak blokady reinstalacji umożliwia zapis dowolnego kodu
An issue was discovered in ShopXO CMS 2.2.0. After entering the management page, there is an arbitrary file up...