CVE-2024-8163

A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. Affected by this issue is the function destroyFiles of the file /admin/file_manager/files. The manipulation of the argument files results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could be used. Upgrading to version 1.6.0 can resolve this issue. You should upgrade the affected component.
References
Link Resource
https://github.com/DeepMountains/zzz/blob/main/CVE4-1.md Exploit Third Party Advisory
https://vuldb.com/?ctiid.275761 Permissions Required
https://vuldb.com/?id.275761 Third Party Advisory
https://vuldb.com/?submit.393374 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:beikeshop:beikeshop:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-08-26 13:15

Updated : 2025-11-24 07:16


NVD link : CVE-2024-8163

Mitre link : CVE-2024-8163

CVE.ORG link : CVE-2024-8163


JSON object : View

Products Affected

beikeshop

  • beikeshop
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')