CVE-2020-19672

CRITICAL

Niushop - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

Niushop B2B2C Multi-business basic version V1.11, can bypass the administrator to obtain the background upload interface, through parameter upload, bypass the getimagesize function, upload php file, getshell.

Scores

CVSS v3 9.8
EPSS 0.0043
EPSS Percentile 62.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
niushop/niushop 1.11
Published Sep 30, 2020
Tracked Since Feb 18, 2026