Vulnerability CVE-2024-22724


Published: 2024-03-21

Description:
An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administrator profile photo upload feature.

 References:
https://medium.com/%40cupc4k3/oscommerce-v4-rce-unveiling-the-file-upload-bypass-threat-f1ac0097880c
https://github.com/osCommerce/osCommerce-V4/issues/62

Copyright 2026, cxsecurity.com

 

Back to Top