CVE-2022-30423

CRITICAL

Merchandise Online Store 1.0 - Remote Code Execution via User Profile Upload

Title source: llm
STIX 2.1

Description

Merchandise Online Store v1.0 by oretnom23 has an arbitrary code execution (RCE) vulnerability in the user profile upload point in the system information.

Scores

CVSS v3 9.8
EPSS 0.0170
EPSS Percentile 74.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
merchandise_online_store_project/merchandise_online_store 1.0
Published Jun 02, 2022
Tracked Since Feb 18, 2026