CVE Published: 28/10/2024 |
CVE Updated: 28/10/2024 |
CVE Year: 2024 Source: Patchstack |
Vendor: BuyNowDepot |
Product: Advanced Online Ordering and Delivery Platform Status : PUBLISHED
CVE-2024-50497 Description
Improper Control of Filename for Include/Require Statement in PHP Program (\'PHP Remote File Inclusion\') vulnerability in BuyNowDepot Advanced Online Ordering and Delivery Platform allows PHP Local File Inclusion.This issue affects Advanced Online Ordering and Delivery Platform: from n/a through 2.0.0.
Metrics
CVSS Version: 3.1 |
Base Score: 8.1 HIGH Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
l➤ Impact Metrics: Confidentiality Impact (C)* HIGH Integrity Impact (I)* HIGH Availability Impact (A)* HIGH
Weakness Enumeration (CWE)
CWE-ID: CWE-98 CWE Name: CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program (
PHP Remote File Inclusion
) Source: BuyNowDepot
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID: CAPEC-252 CAPEC Description: CAPEC-252 PHP Local File Inclusion