Record summary

CVE-2019-16123 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

In Kartatopia PilusCart 1.4.1, the parameter filename in the file catalog.php is mishandled, leading to ../ Local File Disclosure.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBPilusCart 1.4.1 - Local File DisclosureExploitDB exploitby Damian EbeltiesNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHPilusCart <=1.4.1 - Local File InclusionCVSS 7.5

PilusCart versions 1.4.1 and prior suffer from a file disclosure vulnerability via local file inclusion.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, potential data leakage, and remote code execution.

Remediation

Upgrade to a patched version of PilusCart (>=1.4.2) or apply the vendor-supplied patch to mitigate the LFI vulnerability.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscvecve2019piluscartlfipacketstormedbkartatopiavuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:kartatopia:piluscart:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3