CVE-2024-22724 Information

Description

An issue was discovered in osCommerce v4 allows local attackers to bypass file upload restrictions and execute arbitrary code via administrator profile photo upload feature.

Reference

https://medium.com/%40cupc4k3/oscommerce-v4-rce-unveiling-the-file-upload-bypass-threat-f1ac0097880c https://github.com/osCommerce/osCommerce-V4/issues/62

Share on: