6.5
CVSSv3

CVE-2019-8404

Published: 14/05/2019 Updated: 22/05/2019
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 5.2 | Exploitability Score: 1.2
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

An issue exists in Webiness Inventory 2.3. The ProductModel component allows Arbitrary File Upload via a crafted product image during the creation of a new product. Consequently, an attacker can steal information from the site with the help of an installed executable file, or change the contents of pages.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

webiness inventory project webiness inventory 2.3

Exploits

Webiness Inventory version 23 suffers from an arbitrary file upload vulnerability ...