JPShop是一个开源社区团购微商城小程序。 Juanpao JPShop 1.5.02版本及之前版本存在代码问题漏洞,该漏洞源于对参数 pic_url 的错误操作会导致上传不受限制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-1259 | 6.3 MEDIUM | Juanpao JPShop API AppController.php unrestricted upload |
| CVE-2024-1260 | 6.3 MEDIUM | Juanpao JPShop API ComboController.php actionIndex unrestricted upload |
| CVE-2024-1261 | 6.3 MEDIUM | Juanpao JPShop API ComboController.php actionIndex unrestricted upload |
| CVE-2024-1262 | 6.3 MEDIUM | Juanpao JPShop API MaterialController.php actionUpdate unrestricted upload |
| CVE-2024-1264 | 6.3 MEDIUM | Juanpao JPShop UploadsController.php actionUpdate unrestricted upload |
| CVE-2024-1258 | 3.1 LOW | Juanpao JPShop API params.php hard-coded key |
No comments yet