CVE-2018-12256

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
16/08/2018
Last modified:
12/10/2018

Description

admin/vqmods.app/vqmods.inc.php in LiteCart before 2.1.3 allows remote authenticated attackers to upload a malicious file (resulting in remote code execution) by using the text/xml or application/xml Content-Type in a public_html/admin/?app=vqmods&doc=vqmods request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:litecart:litecart:*:*:*:*:*:*:*:* 2.1.3 (excluding)