Description
An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administrator profile photo upload feature.
Remediation
References
Related Vulnerabilities
WordPress Plugin Attach Gallery Posts Cross-Site Scripting (1.6)
WordPress Plugin Advanced Permalinks Cross-Site Scripting (0.1.19)
Django Use of Persistent Cookies Containing Sensitive Information Vulnerability (CVE-2026-35192)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-3327)