What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8.
Explanation of Vulnerability in Simple Terms
XStore Core versions up to 5.3.8 do not properly validate file uploads, allowing an attacker to upload malicious files without authentication. This can lead to site disruption or data corruption. The vulnerability requires no user interaction and can be exploited remotely over the network.
What an attacker can do
Upload malicious files to the site without authentication, disrupting service or corrupting data.
Potential impact on your site
Attackers can upload files that disrupt your site's availability or corrupt stored data without needing a user account.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities