Vulnerabilities > EC Cube > Product Image Bulk Upload > 4.1.0

DATE CVE VULNERABILITY TITLE RISK
2022-09-27 CVE-2022-37346 Unrestricted Upload of File with Dangerous Type vulnerability in Ec-Cube Product Image Bulk Upload 1.0.0/4.1.0
EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files.
network
low complexity
ec-cube CWE-434
critical
9.8