CVE-2022-30423

CRITICAL

Merchandise Online Store - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

Merchandise Online Store v1.0 by oretnom23 has an arbitrary code execution (RCE) vulnerability in the user profile upload point in the system information.

Scores

CVSS v3 9.8
EPSS 0.0102
EPSS Percentile 77.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
merchandise_online_store_project/merchandise_online_store 1.0
Published Jun 02, 2022
Tracked Since Feb 18, 2026