CVE-2022-39977

HIGH

Online Pet Shop WE App - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in the User module. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file uploaded through the picture upload point.

Scores

CVSS v3 7.2
EPSS 0.0099
EPSS Percentile 77.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
online_pet_shop_we_app_project/online_pet_shop_we_app 1.0
Published Oct 27, 2022
Tracked Since Feb 18, 2026