SB2017101223 - Input validation error in Qualiteam X-Cart



SB2017101223 - Input validation error in Qualiteam X-Cart

Published: October 12, 2017 Updated: August 8, 2020

Security Bulletin ID SB2017101223
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Input validation error (CVE-ID: CVE-2017-15285)

The vulnerability allows a remote authenticated user to execute arbitrary code.

X-Cart 5.2.23, 5.3.1.9, 5.3.2.13, and 5.3.3 is vulnerable to Remote Code Execution. This vulnerability exists because the application fails to check remote file extensions before saving locally. This vulnerability can be exploited by anyone with Vendor access or higher. One attack methodology is to upload an image file in the Attachments section of a product catalog, upload a .php file with an "Add File Via URL" action, and change the image's Description URL to reference the .php URL in the attachments/ directory.


Remediation

Install update from vendor's website.