{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ayhx070424shopxo/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:yhx070424:shopxo:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-96898"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ShopXO (\u003c= 2.2.7)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["yhx070424"],"content_html":"\u003cp\u003eShopXO versions up to 2.2.7 contain a path traversal vulnerability located in the Ueditor Upload Interface, specifically within the config/ueditor.php component. The vulnerability is triggered by manipulating the path_type argument during an upload request. This flaw allows a remote, unauthenticated attacker to bypass intended directory restrictions, potentially accessing or manipulating files outside of the application's expected upload path. The vulnerability was disclosed publicly, and proof-of-concept exploit code is currently available. As of the time of reporting, the maintainers have not released a patch to remediate this issue, leaving instances of ShopXO running these versions exposed to potential remote exploitation. Defenders should monitor web server logs for requests targeting the identified component with directory traversal patterns.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an attacker to perform path traversal, leading to unauthorized read or write access to files on the hosting server. This could lead to sensitive information disclosure or, if write access is achieved, potential remote code execution by uploading malicious scripts to the web server.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement egress filtering and restricted filesystem permissions for the web server user to limit the impact of potential path traversal exploitation.\u003c/li\u003e\n\u003cli\u003eDeploy WAF rules to inspect HTTP requests targeting 'config/ueditor.php' for directory traversal sequences like '../' or absolute paths within the 'path_type' parameter.\u003c/li\u003e\n\u003cli\u003eRestrict access to the ShopXO administration and upload endpoints to trusted IP addresses until a patch is provided.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous POST requests containing path traversal payloads directed at the vulnerable component.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T04:46:06Z","date_published":"2026-09-24T04:46:06Z","id":"https://feed.craftedsignal.io/briefs/2026-09-shopxo-path-traversal/","summary":"ShopXO versions up to 2.2.7 are vulnerable to remote path traversal attacks via the path_type argument in the Ueditor Upload Interface, allowing unauthorized file access.","title":"Path Traversal Vulnerability in ShopXO Ueditor Upload Interface","url":"https://feed.craftedsignal.io/briefs/2026-09-shopxo-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:yhx070424:shopxo:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}