Description
A security flaw has been discovered in itsourcecode E-Commerce Website 1.0. Affected is an unknown function of the file /admin/users.php. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit has been released to the public and may be exploited.
In itsourcecode E-Commerce Website 1.0 ist eine Schwachstelle entdeckt worden. Dabei geht es um eine nicht genauer bekannte Funktion der Datei /admin/users.php. Die Manipulation führt zu unrestricted upload. Der Angriff lässt sich über das Netzwerk starten. Der Exploit ist öffentlich verfügbar und könnte genutzt werden.
Problem types
Product status
Timeline
| 2025-09-17: | Advisory disclosed |
| 2025-09-17: | VulDB entry created |
| 2025-09-17: | VulDB entry last update |
Credits
lizis3c (VulDB User)
References
github.com/yihaofuweng/cve/issues/24
vuldb.com/?id.324643 (VDB-324643 | itsourcecode E-Commerce Website users.php unrestricted upload)
vuldb.com/?ctiid.324643 (VDB-324643 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.649912 (Submit #649912 | itsourcecode E-Commerce Website V1.0 V1.0 upload)
github.com/yihaofuweng/cve/issues/24
itsourcecode.com/