Vulnerability Description
Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in the Product List module. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file uploaded through the picture upload point.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Online Pet Shop We App Project | Online Pet Shop We App | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/z1pwn/bug_report/blob/main/vendors/oretnom23/online-pet-shop-ExploitThird Party Advisory
- https://github.com/z1pwn/bug_report/blob/main/vendors/oretnom23/online-pet-shop-ExploitThird Party Advisory
FAQ
What is CVE-2022-39978?
CVE-2022-39978 is a vulnerability with a CVSS score of 7.2 (HIGH). Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in the Product List module. This vulnerability allows attackers to execute arbitra...
How severe is CVE-2022-39978?
CVE-2022-39978 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-39978?
Check the references section above for vendor advisories and patch information. Affected products include: Online Pet Shop We App Project Online Pet Shop We App.