CVE-2024-50648

CRITICAL

yshopmall V1.0 - Arbitrary File Upload and Remote Code Execution via JSP File Parsing

Title source: llm
STIX 2.1

Description

yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.

Scores

CVSS v3 9.8
EPSS 0.0098
EPSS Percentile 57.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-22
Status published
Products (1)
guchengwuyue/yshopmall 1.0
Published Nov 15, 2024
Tracked Since Feb 18, 2026