CVE-2022-26521
10.03.2022, 17:47
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Catalog>Media Manager>Images settings can be changed by an administrator (e.g., by configuring .php to be a valid image file type).Enginsight
Vendor | Product | Version |
---|---|---|
abantecart | abantecart | 𝑥 ≤ 1.3.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References