CVE-2024-50648

CRITICAL

Guchengwuyue Yshopmall - Path Traversal

Title source: rule
STIX 2.1

Description

yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.

Scores

CVSS v3 9.8
EPSS 0.0071
EPSS Percentile 72.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-22
Status published
Products (1)
guchengwuyue/yshopmall 1.0
Published Nov 15, 2024
Tracked Since Feb 18, 2026