1 results (0.035 seconds)

CVSS: 6.5EPSS: 0%CPEs: 7EXPL: 1

14 Jul 2024 — A vulnerability was found in Nanjing Xingyuantu Technology SparkShop up to 1.1.6. It has been rated as critical. This issue affects some unknown processing of the file /api/Common/uploadFile. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. • https://github.com/J1rrY-learn/learn/blob/main/sparkshop_upload.md • CWE-434: Unrestricted Upload of File with Dangerous Type •