CVE-2018-12519

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
19/06/2018
Last modified:
13/08/2018

Description

An issue was discovered in ShopNx through 2017-11-17. The vulnerability allows a remote attacker to upload any malicious file to a Node.js application. An attacker can upload a malicious HTML file that contains a JavaScript payload to steal a user's credentials.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:codenx:shopnx:*:*:*:*:*:node.js:*:*