xnx3 Wangmarket Unrestricted File Upload Vulnerability in XML File Handler

Vulnerability

A vulnerability allowing unrestricted file uploads has been identified in xnx3 Wangmarket versions through 6.4. The issue arises in the 'uploadImage' function of the '/sits/uploadImage.do' file, where the 'image' argument can be manipulated to upload malicious XML files. This vulnerability can be exploited remotely, leading to stored cross-site scripting (XSS) attacks.

Impact

Exploitation of this vulnerability allows for unrestricted file uploads, which can be used to execute malicious scripts on the server, causing stored cross-site scripting (XSS) vulnerabilities.

Reproduction

To reproduce this vulnerability, upload an XML file through the '/sits/uploadImage.do' endpoint. The uploaded file can contain a JavaScript payload that will be executed when the file is accessed, demonstrating the stored XSS vulnerability.

Added: Jan 1, 2026, 10:17 PM
Updated: Jan 1, 2026, 10:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.3
remediation
0.0
relevance
1.8
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.