CVE-2023-26686

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Sep 25, 2024
Updated: Sep 26, 2024
CWE ID 434

Summary

CVE-2023-26686 is a file upload vulnerability affecting CS-Cart MultiVendor version 4.16.1. An attacker can exploit this weakness by uploading malicious image files to the custom shop feature. Successful exploitation grants the attacker the ability to run arbitrary code and potentially gain administrative access to the system. This vulnerability poses a significant risk and necessitates immediate patching for all affected installations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • CS-Cart Multi-Vendor

Affected Vendors

  • CS-Cart