Security Advisory

CVE-2018-12256

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-08-16 20:00:00
Last updated 2024-08-05 08:30:59
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

admin/vqmods.app/vqmods.inc.php in LiteCart before 2.1.3 allows remote authenticated attackers to upload a malicious file (resulting in remote code execution) by using the text/xml or application/xml Content-Type in a public_html/admin/?app=vqmods&doc=vqmods request.