Welcart e-Commerce, de991b08-d234-4ca4-87ef-0beb8a6a0c31
- CVE, Research URL
- Home page URL
- Application
- Published on
- -
- Research Description
- Welcart e-Commerce [usc-e-shop] < 2.9.6 Welcart e-Commerce < 2.9.6 - Admin+ PHP Object Injection The plugin is vulnerable to PHP Object Injection in all versions up to 2.9.5 (inclusive) via deserialization of untrusted input in the welcart_confirm_check_ajax function. This makes it possible for administrators to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
- Affected versions
-
max 2.9.6.
- Status
-
vulnerable