Description
A vulnerability was identified in h-moses moga-mall up to 392d631a5ef15962a9bddeeb9f1269b9085473fa. This vulnerability affects the function addProduct of the file src/main/java/com/ms/product/controller/PmsProductController.java. Such manipulation of the argument objectName leads to unrestricted upload. The attack may be performed from remote. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed.
Problem types
Product status
Timeline
| 2025-12-27: | Advisory disclosed |
| 2025-12-27: | VulDB entry created |
| 2025-12-27: | VulDB entry last update |
Credits
zyhsec (VulDB User)
References
vuldb.com/?id.338529 (VDB-338529 | h-moses moga-mall PmsProductController.java addProduct unrestricted upload)
vuldb.com/?ctiid.338529 (VDB-338529 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.721988 (Submit #721988 | https://github.com/h-moses/moga-mall moga-mall 1.0 Upload any file)
github.com/...r/cve/blob/main/moga-mall任意文件上传.md