8.8
CVSSv3

CVE-2018-10258

Published: 01/05/2018 Updated: 24/08/2020
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

A CSV Injection vulnerability exists in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

Vulnerable Product Search on Vulmon Subscribe to Product

codeslab shopy point of sale 1.0

Exploits

# Exploit Title: Shopy Point of Sale v10 - CSV Injection # Date: 2018-04-23 # Exploit Author: 8bitsec # CVE: CVE-2018-10258 # Vendor Homepage: codecanyonnet/ # Software Link: codecanyonnet/item/shopy-point-of-sales/21730225 # Version: 10 # Tested on: [Kali Linux 20 | Mac OS 1013] Release Date: ============= 2018-04-23 Produc ...
Shopy Point of Sale version 10 suffers from a CSV injection vulnerability ...