CVE-2022-39977

HIGH

Online Pet Shop We App 1.0 - Arbitrary File Upload and Remote Code Execution via User Module Picture Upload

Title source: llm
STIX 2.1

Description

Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in the User module. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file uploaded through the picture upload point.

Scores

CVSS v3 7.2
EPSS 0.0106
EPSS Percentile 60.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
online_pet_shop_we_app_project/online_pet_shop_we_app 1.0
Published Oct 27, 2022
Tracked Since Feb 18, 2026