CVE-2018-12519: Codenx Shopnx
High severity, CVSS 8.8. EPSS: 7.8% chance of exploitation in the next 30 days.
An issue was discovered in ShopNx through 2017-11-17. The vulnerability allows a remote attacker to upload any malicious file to a Node.js application. An attacker can upload a malicious HTML file that contains a JavaScript payload to steal a user's credentials.
Affected products
- Codenx Shopnx: any version
Published 2018-06-19. Last modified 2026-06-17.