What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in radykal Fancy Product Designer fancy-product-designer.This issue affects Fancy Product Designer: from n/a through <= 6.4.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in radykal Fancy Product Designer fancy-product-designer.This issue affects Fancy Product Designer: from n/a through <= 6.4.3.
Explanation of Vulnerability in Simple Terms
Fancy Product Designer versions 6.4.3 and earlier allow unauthenticated attackers to upload arbitrary files to the server. The vulnerability requires specific conditions to exploit but can result in complete compromise of the site, including data theft, modification, and service disruption. Administrators should update immediately to a patched version.
What an attacker can do
Upload malicious files to the server and execute code on the site without authentication.
Potential impact on your site
Complete site compromise possible: attackers can steal data, modify content, or take the site offline.
Conditions required to exploit
Network access to the site; specific attack complexity conditions must be met.
Key dates
External resources
Related vulnerabilities