Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in ShopXO 1.2.0. In the application\install\controller\Index.php file, there is no validation lock file in the Add method, which allows an attacker to reinstall the database. The attacker can write arbitrary code to database.php during system reinstallation.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ShopXO 权限许可和访问控制问题漏洞
Vulnerability Description
ShopXO是一套开源的企业级开源电子商务系统。 ShopXO 1.2.0版本中的applicationinstallcontrollerIndex.php文件存在安全漏洞,该漏洞源于在Add方法中程序没有校验锁文件。攻击者可利用该漏洞重新安装数据库,并在系统重安装过程中向database.php文件写入任意代码。
CVSS Information
N/A
Vulnerability Type
N/A