Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-100658. PoCs published by Alessandro Magnosi.
AI-analyzed exploit summary This exploit targets a privilege escalation vulnerability in NopCommerce 4.2.0, allowing an authenticated attacker to upload a malicious .cshtml file via directory traversal in the RoxyFileman component, resulting in remote code execution (RCE). The PoC includes a fully functional web shell for command execution.
Description
NopCommerce 4.2.0 - Privilege Escalation
Exploits (1)
This exploit targets a privilege escalation vulnerability in NopCommerce 4.2.0, allowing an authenticated attacker to upload a malicious .cshtml file via directory traversal in the RoxyFileman component, resulting in remote code execution (RCE). The PoC includes a fully functional web shell for command execution.