Laiketui

Laiketui

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 15.09.2023 16:15:08
  • Zuletzt bearbeitet 21.11.2024 08:36:24

A vulnerability, which was classified as problematic, was found in Bettershop LaikeTui. This affects an unknown part of the file index.php?module=system&action=uploadImg. The manipulation of the argument imgFile leads to unrestricted upload. It is po...

  • EPSS 0.06%
  • Veröffentlicht 27.08.2023 23:15:36
  • Zuletzt bearbeitet 21.11.2024 08:35:25

A vulnerability, which was classified as critical, has been found in Bettershop LaikeTui. Affected by this issue is some unknown functionality of the file index.php?module=api&action=user&m=upload of the component POST Request Handler. The manipulati...

Exploit
  • EPSS 1.02%
  • Veröffentlicht 23.06.2022 17:15:11
  • Zuletzt bearbeitet 21.11.2024 06:25:08

Laiketui 3.5.0 is affected by an arbitrary file upload vulnerability that can allow an attacker to execute arbitrary code.

Exploit
  • EPSS 0.27%
  • Veröffentlicht 23.06.2022 17:15:11
  • Zuletzt bearbeitet 21.11.2024 06:25:08

SQL injection exists in LaiKetui v3.5.0 the background administrator list.

Exploit
  • EPSS 0.26%
  • Veröffentlicht 23.06.2022 17:15:11
  • Zuletzt bearbeitet 21.11.2024 06:25:08

LaiKetui v3.5.0 has SQL injection in the background through the menu management function, and sensitive data can be obtained.

Exploit
  • EPSS 0.45%
  • Veröffentlicht 15.09.2021 14:15:08
  • Zuletzt bearbeitet 21.11.2024 05:08:59

Cross Site Request Forgery (CSRF) in LaikeTui v3 allows remote attackers to execute arbitrary code via the component '/index.php?module=member&action=add'.

Exploit
  • EPSS 0.74%
  • Veröffentlicht 15.06.2021 20:15:14
  • Zuletzt bearbeitet 21.11.2024 06:09:56

LaikeTui 3.5.0 allows remote authenticated users to execute arbitrary PHP code by using index.php?module=system&action=pay to upload a ZIP archive containing a .php file, as demonstrated by the ../../../../phpinfo.php pathname.

Exploit
  • EPSS 0.87%
  • Veröffentlicht 15.06.2021 20:15:14
  • Zuletzt bearbeitet 21.11.2024 06:09:56

LaikeTui 3.5.0 allows remote authenticated users to delete arbitrary files, as demonstrated by deleting install.lock in order to reinstall the product in an attacker-controlled manner. This deletion is possible via directory traversal in the uploadIm...