8.8
CVSSv3

CVE-2018-12519

Published: 19/06/2018 Updated: 13/08/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

An issue exists in ShopNx through 2017-11-17. The vulnerability allows a remote malicious user to upload any malicious file to a Node.js application. An attacker can upload a malicious HTML file that contains a JavaScript payload to steal a user's credentials.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

codenx shopnx

Exploits

# Exploit Title: ShopNx - Angular5 Single Page Shopping Cart Application 1 - Arbitrary File Upload # Date: 2018-07-03 # Exploit Author: L0RD # Email: bornanematzadeh123@gmailcom # Vendor Homepage: codenxcom/ # Version: 1 # CVE: CVE-2018-12519 # Tested on: Win 10 =================================================== # Description : ShopNx 1 ...
ShopNx suffers from an arbitrary file upload vulnerability ...