Description
A vulnerability was found in ShopXO up to 6.1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file extend/base/Uploader.php. The manipulation of the argument source leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-270367. NOTE: The original disclosure confuses CSRF with SSRF.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2319 | A vulnerability was found in ShopXO up to 6.1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file extend/base/Uploader.php. The manipulation of the argument source leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-270367. NOTE: The original disclosure confuses CSRF with SSRF. |
Github GHSA |
GHSA-c96r-38gv-grp4 | ShopXO Server-Side Request Forgery Vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-08-01T21:41:03.538Z
Reserved: 2024-07-05T04:50:36.117Z
Link: CVE-2024-6524
Updated: 2024-08-01T21:41:03.538Z
Status : Modified
Published: 2024-07-05T12:15:02.090
Modified: 2024-11-21T09:49:48.110
Link: CVE-2024-6524
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA