CyberRota Analysis
AI-GeneratedAn Unrestricted File Upload vulnerability in xShop version 3.0.3 allows authenticated administrators to upload malicious executable files, potentially leading to Remote Code Execution (RCE) and full system compromise. Organizations using this version should prioritize patching to version 3.0.4 to mitigate the critical risk associated with this vulnerability. Immediate action is essential for any entity relying on xShop for their operations.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administrator to upload executable files (e.g., .php). By uploading a specially crafted php file, an attacker can achieve Remote Code Execution (RCE) on the server, leading to a full system compromise. Version 3.0.4 fixes the issue.