CVE-2024-6524
A vulnerability was found in ShopXO up to 6.1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file extend/base/Uploader.php. The manipulation of the argument source leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-270367. NOTE: The original disclosure confuses CSRF with SSRF.
- Affected products
- Shopxo
- Shopxo
- ≤ 6.1.0
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 0.5% (39th percentile)
- Weakness
- CWE-918
- NVD status
- Modified
- Published
- 2024-07-05
CVE-2024-6524 at NVD
No indexed exploits for CVE-2024-6524 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-6524 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.