Vulnerabilities > Nopcommerce

DATE CVE VULNERABILITY TITLE RISK
2019-12-09 CVE-2019-19684 Unrestricted Upload of File with Dangerous Type vulnerability in Nopcommerce 4.20
nopCommerce v4.2.0 allows privilege escalation via file upload in Presentation/Nop.Web/Admin/Areas/Controllers/PluginController.cs via Admin/FacebookAuthentication/Configure because it is possible to upload a crafted Facebook Auth plugin.
network
low complexity
nopcommerce CWE-434
6.5
2019-12-09 CVE-2019-19683 Path Traversal vulnerability in Nopcommerce 4.20
RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to ../ path traversal via d or f to Admin/RoxyFileman/ProcessRequest because of Libraries/Nop.Services/Media/RoxyFileman/FileRoxyFilemanService.cs.
network
low complexity
nopcommerce CWE-22
critical
9.0
2019-12-09 CVE-2019-19682 Cross-site Scripting vulnerability in Nopcommerce 4.20
nopCommerce through 4.20 allows XSS in the SaveStoreMappings of the components \Presentation\Nop.Web\Areas\Admin\Controllers\NewsController.cs and \Presentation\Nop.Web\Areas\Admin\Controllers\BlogController.cs via Body or Full to Admin/News/NewsItemEdit/[id] Admin/Blog/BlogPostEdit/[id].
3.5
2019-04-25 CVE-2019-11519 XXE vulnerability in Nopcommerce
Libraries/Nop.Services/Localization/LocalizationService.cs in nopCommerce through 4.10 allows XXE via the "Configurations -> Languages -> Edit Language -> Import Resources -> Upload XML file" screen.
network
low complexity
nopcommerce CWE-611
4.0