(adsbygoogle = window.adsbygoogle []).push();NOTE: If you need, I will send you a demo video, please use this mail: nu11secur...@gmail.com!If don't care about this, please just leave this email! somewhere in the past!KR your friend @nu11secur1ty## Title: emart-Laravel-Multi-Vendor-eCommerce-Advanced-CMS-V 5.0 (RELEASE 3.9.0) File Upload-RCE## Author: nu11secur1ty## Date: 11/22/2023## Vendor: Software: -laravel-multivendor-ecommerce-advanced-cms/25300293?s_rank=7## Reference: -security/file-upload, -security/file-upload/lab-file-upload-remote-code-execution-via-web-shell-upload## Description:In the menu to the option - category, the id parameter is vulnerable to File Upload and RCE attacks, it is not sanitized correctly.The attacker can upload a virus directly on the server by using this web vulnerability, and then he can execute it, this can bethe end of this server, depending on the scenario! In this case, I just upload a javascript WebSocket, this is very dangerous, it depends on the scenario!STATUS: HIGH-CRITICAL Vulnerability## Reproduce:[href]( -nu11secur1ty/tree/main/vendors/media-city/emart-Laravel-Multi-Vendor-eCommerce-Advanced-CMS-V%205.0)## Proof and Exploit:[href]( -laravel-multi-vendor-ecommerce.html)## Time spent:01:17:00--System Administrator - Infrastructure EngineerPenetration Testing EngineerExploit developer at ://cxsecurity.com/ and -db.com/0day Exploit DataBase page: +SEH9gBclAAYWGnPoBIQ75sCj60E=nu11secur1ty
Download Zip ✒ ✒ ✒ https://t.co/QfaDxKXj4J