CVE-2024-50648

yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.
CVSS

No CVSS.

References
Configurations

Configuration 1 (hide)

cpe:2.3:a:guchengwuyue:yshopmall:1.0:*:*:*:*:*:*:*

History

17 Jun 2025, 01:19

Type Values Removed Values Added
First Time Guchengwuyue yshopmall
Guchengwuyue
CPE cpe:2.3:a:guchengwuyue:yshopmall:1.0:*:*:*:*:*:*:*
References () https://github.com/Yllxx03/CVE/tree/main/CVE-2024-50648 - () https://github.com/Yllxx03/CVE/tree/main/CVE-2024-50648 - Exploit, Third Party Advisory
References () https://github.com/Yllxx03/CVE/blob/main/yshop_fileu_pload.md - () https://github.com/Yllxx03/CVE/blob/main/yshop_fileu_pload.md - Exploit, Third Party Advisory

15 Nov 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-15 16:15

Updated : 2025-06-17 01:19


NVD link : CVE-2024-50648

Mitre link : CVE-2024-50648


JSON object : View

Products Affected

guchengwuyue

  • yshopmall
CWE

No CWE.