yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.
History

Tue, 17 Jun 2025 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Guchengwuyue
Guchengwuyue yshopmall
CPEs cpe:2.3:a:guchengwuyue:yshopmall:1.0:*:*:*:*:*:*:*
Vendors & Products Guchengwuyue
Guchengwuyue yshopmall

Tue, 03 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Yshopmall
Yshopmall yshopmall
Weaknesses CWE-22
CPEs cpe:2.3:a:yshopmall:yshopmall:*:*:*:*:*:*:*:*
Vendors & Products Yshopmall
Yshopmall yshopmall
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 15 Nov 2024 16:00:00 +0000

Type Values Removed Values Added
Description yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-11-15T00:00:00

Updated: 2024-12-03T16:35:37.378Z

Reserved: 2024-10-28T00:00:00

Link: CVE-2024-50648

cve-icon Vulnrichment

Updated: 2024-12-03T16:35:32.061Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-15T16:15:36.547

Modified: 2025-06-17T01:19:01.617

Link: CVE-2024-50648

cve-icon Redhat

No data.