3 results (0.001 seconds)

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

09 Oct 2024 — A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products. • http://sparkshop.com • CWE-841: Improper Enforcement of Behavioral Workflow •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

16 Jul 2024 — File Upload vulnerability in Nanjin Xingyuantu Technology Co Sparkshop (Spark Mall B2C Mall v.1.1.6 and before allows a remote attacker to execute arbitrary code via the contorller/common.php component. Vulnerabilidad de carga de archivos en Nanjin Xingyuantu Technology Co Sparkshop (Spark Mall B2C Mall v.1.1.6 y anteriores permite a un atacante remoto ejecutar código arbitrario a través del componente contorller/common.php. • https://gist.github.com/J1rrY-learn/26524d4714a81cf2d64583069e96f765 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 6.5EPSS: 0%CPEs: 7EXPL: 1

14 Jul 2024 — A vulnerability was found in Nanjing Xingyuantu Technology SparkShop up to 1.1.6. It has been rated as critical. This issue affects some unknown processing of the file /api/Common/uploadFile. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. • https://github.com/J1rrY-learn/learn/blob/main/sparkshop_upload.md • CWE-434: Unrestricted Upload of File with Dangerous Type •