CVE-2024-6524 is a critical Server-Side Request Forgery (SSRF) vulnerability affecting ShopXO up to version 6.1.0, specifically within the extend/base/Uploader.php file. This flaw allows remote attackers to manipulate the 'source' argument, forcing the server to make requests to arbitrary locations. With a CVSS score of 8.8 (High), it presents a significant risk due to its low attack complexity and potential for high impact on confidentiality, integrity, and availability. While no active exploitation or public exploit intelligence (Metasploit, Nuclei, ExploitDB) has been identified, the vulnerability has been publicly disclosed, increasing the likelihood of future exploitation. Community discussion and media coverage remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.1.0CPE matchmatch criteria | cpe:2.3:a:shopxo:shopxo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.