This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Niushop First view 2019-09-14
Product Niushop Last view 2020-09-30
Version Type Application
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:niushop:niushop:1.11:*:*:*:*:*:*:* 4

Related : CVE

  Date Alert Description
9.8 2020-09-30 CVE-2020-19672

Niushop B2B2C Multi-business basic version V1.11, can bypass the administrator to obtain the background upload interface, through parameter upload, bypass the getimagesize function, upload php file, getshell.

4.9 2020-09-30 CVE-2020-19670

In Niushop B2B2C Multi-Business Basic Edition V1.11, authentication can be bypassed, causing administrators to reset any passwords.

8.8 2019-09-14 CVE-2019-16311

NIUSHOP V1.11 has CSRF via search_info to index.php.

5.4 2019-09-14 CVE-2019-16310

NIUSHOP V1.11 has XSS via the index.php?s=/admin URI.

CWE : Common Weakness Enumeration

%idName
25% (1) CWE-434 Unrestricted Upload of File with Dangerous Type
25% (1) CWE-352 Cross-Site Request Forgery (CSRF)
25% (1) CWE-306 Missing Authentication for Critical Function
25% (1) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')