What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in Soft8Soft LLC Verge3D Publishing and E-Commerce.This issue affects Verge3D Publishing and E-Commerce: from n/a through 4.5.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in Soft8Soft LLC Verge3D Publishing and E-Commerce.This issue affects Verge3D Publishing and E-Commerce: from n/a through 4.5.2.
Explanation of Vulnerability in Simple Terms
Verge3D Publishing and E-Commerce versions up to 4.5.2 do not properly validate file uploads, allowing an authenticated attacker to upload malicious files. An attacker with low-level access can upload files that may execute on the server or be served to site visitors. This vulnerability affects confidentiality, integrity, and availability of the affected system.
What an attacker can do
Upload and execute malicious files on the server or distribute them to site visitors.
Potential impact on your site
An authenticated user can upload files that compromise your server, deface content, or infect visitors.
Conditions required to exploit
Attacker must have a low-level user account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities