📦 Likeshop

by Likeshop

🔍 What is Likeshop?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-34949

HIGH CVSS 8.2 May 20, 2024

This SQL injection vulnerability in Likeshop allows attackers to execute arbitrary SQL commands through the OrderLogic::getOrderList function at the /admin/order/lists.html endpoint. Attackers can pot...

CVE-2024-0352

HIGH CVSS 7.3 Jan 9, 2024

This critical vulnerability in Likeshop allows attackers to upload arbitrary files without restrictions via the FileServer::userFormImage function. Remote attackers can exploit this to upload maliciou...

CVE-2024-41432

MEDIUM CVSS 5.3 Aug 7, 2024

This CVE describes an IP spoofing vulnerability in Likeshop that allows attackers to forge X-Forwarded or Client-IP headers to bypass IP-based security controls. Attackers can circumvent admin account...