CVE-2024-31823: Ecommerce-Codeigniter-Bootstrap Project Ecommerce-Codeigniter-Bootstrap

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the removeSecondaryImage method of the Publish.php component.

Affected products

Published 2024-04-29. Last modified 2026-08-24.