CVE-2024-8165 is a path traversal vulnerability affecting Chengdu Everbrite Network Technology BeikeShop versions up to 1.5.5, specifically within the exportZip function of the /admin/file_manager/export file. This vulnerability allows an authenticated attacker to remotely manipulate the 'path' argument, potentially leading to unauthorized access to sensitive information. With a CVSS score of 6.5 (Medium), it presents a moderate risk due to its low attack complexity and high confidentiality impact, though it requires authentication. An exploit is publicly available, increasing the risk of exploitation, but there is currently no evidence of active exploitation, Metasploit modules, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.5.5CPE matchmatch criteria | cpe:2.3:a:beikeshop:beikeshop:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.