CVE-2024-8163

A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. Affected by this issue is the function destroyFiles of the file /admin/file_manager/files. The manipulation of the argument files results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could be used. Upgrading to version 1.6.0 can resolve this issue. You should upgrade the affected component.
References
Link Resource
https://github.com/DeepMountains/zzz/blob/main/CVE4-1.md Exploit Third Party Advisory
https://vuldb.com/?ctiid.275761 Permissions Required
https://vuldb.com/?id.275761 Third Party Advisory
https://vuldb.com/?submit.393374 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:beikeshop:beikeshop:*:*:*:*:*:*:*:*

History

24 Nov 2025, 07:16

Type Values Removed Values Added
Summary (en) A vulnerability classified as critical was found in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. Affected by this vulnerability is the function destroyFiles of the file /admin/file_manager/files. The manipulation of the argument files leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. (en) A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. Affected by this issue is the function destroyFiles of the file /admin/file_manager/files. The manipulation of the argument files results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could be used. Upgrading to version 1.6.0 can resolve this issue. You should upgrade the affected component.

Information

Published : 2024-08-26 13:15

Updated : 2025-11-24 07:16


NVD link : CVE-2024-8163

Mitre link : CVE-2024-8163

CVE.ORG link : CVE-2024-8163


JSON object : View

Products Affected

beikeshop

  • beikeshop
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')