What the vulnerability does
01Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Soft8Soft LLC Verge3D Publishing and E-Commerce.This issue affects Verge3D Publishing and E-Commerce: from n/a through 4.5.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Improper Control of Generation of Code ('Code Injection') vulnerability in Soft8Soft LLC Verge3D Publishing and E-Commerce.This issue affects Verge3D Publishing and E-Commerce: from n/a through 4.5.2.
Explanation of Vulnerability in Simple Terms
Verge3D Publishing and E-Commerce versions up to 4.5.2 contain a code injection vulnerability that allows high-privileged users to run arbitrary code on the server. The vulnerability exists due to insufficient input validation in a code execution pathway. An attacker with administrative or equivalent access can inject malicious code that executes with full server privileges, potentially compromising the entire application and underlying system.
What an attacker can do
Run arbitrary code on the server with full application privileges.
Potential impact on your site
A compromised admin account can execute arbitrary code, leading to complete site takeover, data theft, or malware installation.
Conditions required to exploit
Attacker must have high-level administrative access to the Verge3D application.
Key dates
External resources
Related vulnerabilities