Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-39980 | EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files. Exploiting this vulnerability allows a remote unauthenticated attacker to upload arbitrary files other than image files. If a user with an administrative privilege of EC-CUBE where the vulnerable plugin is installed is led to upload a specially crafted file, an arbitrary script may be executed on the system. |
Wed, 21 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2025-05-21T18:25:42.293Z
Reserved: 2022-09-09T00:00:00.000Z
Link: CVE-2022-37346
Updated: 2024-08-03T10:29:20.770Z
Status : Modified
Published: 2022-09-27T23:15:14.540
Modified: 2025-05-21T19:15:57.043
Link: CVE-2022-37346
No data.
OpenCVE Enrichment
No data.
EUVD