Metrics
Affected Vendors & Products
Mon, 24 Nov 2025 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability, which was classified as critical, has been found in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. Affected by this issue is the function rename of the file /Admin/Http/Controllers/FileManagerController.php. The manipulation of the argument new_name leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | A vulnerability was determined in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. This affects the function rename of the file /Admin/Http/Controllers/FileManagerController.php. This manipulation of the argument new_name causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.6.0 is able to mitigate this issue. The affected component should be upgraded. |
| Weaknesses | CWE-284 | |
| Metrics |
cvssV2_0
|
cvssV2_0
|
Fri, 06 Sep 2024 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Beikeshop beikeshop
|
|
| CPEs | cpe:2.3:a:beikeshop:beikeshop:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Beikeshop beikeshop
|
Wed, 28 Aug 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Beikeshop
Beikeshop chengdu Everbrite Network Technology |
|
| CPEs | cpe:2.3:a:beikeshop:chengdu_everbrite_network_technology:1.5.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Beikeshop
Beikeshop chengdu Everbrite Network Technology |
|
| Metrics |
ssvc
|
Mon, 26 Aug 2024 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability, which was classified as critical, has been found in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. Affected by this issue is the function rename of the file /Admin/Http/Controllers/FileManagerController.php. The manipulation of the argument new_name leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Chengdu Everbrite Network Technology BeikeShop FileManagerController.php rename unrestricted upload | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2024-08-26T13:31:04.258Z
Updated: 2025-11-24T06:20:49.733Z
Reserved: 2024-08-26T07:22:16.655Z
Link: CVE-2024-8164
Updated: 2024-08-28T14:56:46.813Z
Status : Modified
Published: 2024-08-26T14:15:08.063
Modified: 2025-11-24T07:16:04.273
Link: CVE-2024-8164
No data.