Vulnerability Description
X-Cart 5.2.23, 5.3.1.9, 5.3.2.13, and 5.3.3 is vulnerable to Remote Code Execution. This vulnerability exists because the application fails to check remote file extensions before saving locally. This vulnerability can be exploited by anyone with Vendor access or higher. One attack methodology is to upload an image file in the Attachments section of a product catalog, upload a .php file with an "Add File Via URL" action, and change the image's Description URL to reference the .php URL in the attachments/ directory.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualiteam | X-Cart | 5.2.23 |
Related Weaknesses (CWE)
References
- https://sxcurity.github.io/PHP%20Code%20Injection%20in%20X-Cart.pdfExploitThird Party Advisory
- https://sxcurity.github.io/PHP%20Code%20Injection%20in%20X-Cart.pdfExploitThird Party Advisory
FAQ
What is CVE-2017-15285?
CVE-2017-15285 is a vulnerability with a CVSS score of 8.8 (HIGH). X-Cart 5.2.23, 5.3.1.9, 5.3.2.13, and 5.3.3 is vulnerable to Remote Code Execution. This vulnerability exists because the application fails to check remote file extensions before saving locally. This ...
How severe is CVE-2017-15285?
CVE-2017-15285 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-15285?
Check the references section above for vendor advisories and patch information. Affected products include: Qualiteam X-Cart.