CVE-2022-26521
HIGHAbantecart <= 1.3.2 - Authenticated Remote Code Execution via Media Manager Image Upload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-26521. PoCs published by Sarang Tumne.
AI-analyzed exploit summary This exploit leverages an authenticated file upload vulnerability in Abantecart v1.3.2 by modifying allowed file extensions to upload a PHP shell, leading to remote code execution. The PoC demonstrates a reverse shell connection upon successful exploitation.
Description
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Catalog>Media Manager>Images settings can be changed by an administrator (e.g., by configuring .php to be a valid image file type).
Exploits (1)
This exploit leverages an authenticated file upload vulnerability in Abantecart v1.3.2 by modifying allowed file extensions to upload a PHP shell, leading to remote code execution. The PoC demonstrates a reverse shell connection upon successful exploitation.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H