#VU93479 External Control of File Name or Path in Aimeos shop and e-commerce framework
Published: June 28, 2024
Aimeos shop and e-commerce framework
Aimeos
Description
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to the affected extension permits specifying the file extension for uploaded product images. A remote user can upload a specially crafted image file with a PHP executable extension and execute arbitrary code on the target system.