cubecart / v6

CubeCart Version 6

Home Page:https://cubecart.com

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Security: Arbitrary File Upload Leads to RCE

abrookbanks opened this issue · comments

Many thanks to Julio Araujo (@julio-cfa) for disclosing this vulnerability responsibly.

Thank you, @abrookbanks! I appreciate the quick fix.

How can we fix this?

Many thanks to Julio Araujo (@julio-cfa) for disclosing this vulnerability responsibly.

Upgrade to the latest version or apply the code changes in this issue.