Erupt Arbitrary File Upload Vulnerability Allowing Code Execution
Vulnerability
A vulnerability allowing arbitrary file upload has been identified in Erupt version 1.12.19. This issue resides in the image upload component of the GoodsCategory section. The vulnerability enables attackers to execute arbitrary code by uploading a crafted file, potentially allowing full control over the website by, for example, uploading a web shell.
Impact
Exploitation of this vulnerability could lead to arbitrary code execution on the server.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
10.0exploitability
8.1remediation
0.0relevance
0.0threat
3.2urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
