CVE-2023-4988
- EPSS 0.15%
- Veröffentlicht 15.09.2023 16:15:08
- Zuletzt bearbeitet 21.11.2024 08:36:24
A vulnerability, which was classified as problematic, was found in Bettershop LaikeTui. This affects an unknown part of the file index.php?module=system&action=uploadImg. The manipulation of the argument imgFile leads to unrestricted upload. It is po...
CVE-2023-4559
- EPSS 0.06%
- Veröffentlicht 27.08.2023 23:15:36
- Zuletzt bearbeitet 21.11.2024 08:35:25
A vulnerability, which was classified as critical, has been found in Bettershop LaikeTui. Affected by this issue is some unknown functionality of the file index.php?module=api&action=user&m=upload of the component POST Request Handler. The manipulati...
CVE-2021-40954
- EPSS 1.02%
- Veröffentlicht 23.06.2022 17:15:11
- Zuletzt bearbeitet 21.11.2024 06:25:08
Laiketui 3.5.0 is affected by an arbitrary file upload vulnerability that can allow an attacker to execute arbitrary code.
CVE-2021-40955
- EPSS 0.27%
- Veröffentlicht 23.06.2022 17:15:11
- Zuletzt bearbeitet 21.11.2024 06:25:08
SQL injection exists in LaiKetui v3.5.0 the background administrator list.
CVE-2021-40956
- EPSS 0.26%
- Veröffentlicht 23.06.2022 17:15:11
- Zuletzt bearbeitet 21.11.2024 06:25:08
LaiKetui v3.5.0 has SQL injection in the background through the menu management function, and sensitive data can be obtained.
CVE-2020-19159
- EPSS 0.45%
- Veröffentlicht 15.09.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 05:08:59
Cross Site Request Forgery (CSRF) in LaikeTui v3 allows remote attackers to execute arbitrary code via the component '/index.php?module=member&action=add'.
CVE-2021-34128
- EPSS 0.74%
- Veröffentlicht 15.06.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 06:09:56
LaikeTui 3.5.0 allows remote authenticated users to execute arbitrary PHP code by using index.php?module=system&action=pay to upload a ZIP archive containing a .php file, as demonstrated by the ../../../../phpinfo.php pathname.
CVE-2021-34129
- EPSS 0.87%
- Veröffentlicht 15.06.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 06:09:56
LaikeTui 3.5.0 allows remote authenticated users to delete arbitrary files, as demonstrated by deleting install.lock in order to reinstall the product in an attacker-controlled manner. This deletion is possible via directory traversal in the uploadIm...