Releases0
Stars858
电商商城 小程序电商商城系统 PC商城 H5商城 APP商城 Java商城 O2O商城 跨境商城 SAAS架构

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL7.5 HIGH

Laiketui 3.5.0 is affected by an arbitrary file upload vulnerability that can allow an attacker to execute arbitrary code.

7.2 HIGH6.5 MEDIUM

SQL injection exists in LaiKetui v3.5.0 the background administrator list.

7.5 HIGH5 MEDIUM

LaiKetui v3.5.0 has SQL injection in the background through the menu management function, and sensitive data can be obtained.

8.8 HIGH6.5 MEDIUM

LaikeTui 3.5.0 allows remote authenticated users to execute arbitrary PHP code by using index.php?module=system&action=pay to upload a ZIP archive containing a .php file, as demonstrated by the ../../../../phpinfo.php pathname.

8.1 HIGH5.5 MEDIUM

LaikeTui 3.5.0 allows remote authenticated users to delete arbitrary files, as demonstrated by deleting install.lock in order to reinstall the product in an attacker-controlled manner. This deletion is possible via directory traversal in the uploadImg, oldpic, or imgurl parameter.