Chengdu Everbrite Network Technology BeikeShop FileManagerController.php rename unrestricted upload
Vulnerability Description
A vulnerability was determined in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. This affects the function rename of the file /Admin/Http/Controllers/FileManagerController.php. This manipulation of the argument new_name causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.6.0 is able to mitigate this issue. The affected component should be upgraded.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-8164
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- wanglun (VulDB User)
References
Affected Vendor
Chengdu Everbrite Network Technology
View all reports →