CVE-2021-27817
15.03.2021, 17:15
A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar where the suffix is JPG, which is uploaded after modifying the phar suffix.Enginsight
| Vendor | Product | Version |
|---|---|---|
| shopxo | shopxo | 1.9.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration