CVE-2024-50648

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
15/11/2024
Last modified:
17/06/2025

Description

yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:guchengwuyue:yshopmall:1.0:*:*:*:*:*:*:*