CVE-2024-31823: Ecommerce-Codeigniter-Bootstrap Project Ecommerce-Codeigniter-Bootstrap
Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the removeSecondaryImage method of the Publish.php component.
Affected products
- Ecommerce-Codeigniter-Bootstrap Project Ecommerce-Codeigniter-Bootstrap: version 2024-01-02 only
Published 2024-04-29. Last modified 2026-08-24.