Vulnerability Description
yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Guchengwuyue | Yshopmall | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/Yllxx03/CVE/blob/main/yshop_fileu_pload.mdExploitThird Party Advisory
- https://github.com/Yllxx03/CVE/tree/main/CVE-2024-50648ExploitThird Party Advisory
FAQ
What is CVE-2024-50648?
CVE-2024-50648 is a vulnerability with a CVSS score of 9.8 (CRITICAL). yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.
How severe is CVE-2024-50648?
CVE-2024-50648 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-50648?
Check the references section above for vendor advisories and patch information. Affected products include: Guchengwuyue Yshopmall.