CVE-2019-25760 | Joomtech Easy Shop 1.2.3 Configuration index.php option filename control (Exploit 46219 / EDB-46219)
A vulnerability was found in Joomtech Easy Shop 1.2.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file index.php of the component Configuration Handler. Executing a manipulation of the argument option can lead to improper control of filename for include/require statement in php program (‘php remote file inclusion’).
This vulnerability is registered as CVE-2019-25760. The attack needs to be launched locally. Furthermore, an exploit is available.VulDB Recent EntriesRead More