{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/iwebshop-5--5.15/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:aircheng_org:iwebshop_5:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-86666"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["iWebShop-5 (\u003c= 5.15)"],"_cs_severities":["high"],"_cs_tags":["web-application","file-upload","vulnerability"],"_cs_type":"advisory","_cs_vendors":["aircheng-org"],"content_html":"\u003cp\u003eA high-severity unrestricted file upload vulnerability, identified as CVE-2026-86666, exists in iWebShop-5 versions up to 5.15. The vulnerability is located within the uploadFile function of the controllers/pic.php file. Remote attackers can leverage this flaw to upload malicious files, such as web shells, to the web server, potentially leading to remote code execution. Public exploit code for this vulnerability is currently available, and the vendor has not yet addressed the issue. Organizations using iWebShop-5 are at risk of compromise and should restrict access to the affected upload functionality until a security patch is provided.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for remote file upload, which is a precursor to full system compromise or web defacement. Because the exploit is publicly available, the risk of automated or targeted exploitation is elevated. Organizations hosting e-commerce platforms using the affected versions of iWebShop are highly susceptible to malicious file drops and subsequent code execution.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement request filtering at the web application firewall (WAF) to inspect POST requests directed to /controllers/pic.php for suspicious file extensions or content types.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous requests to the uploadFile function.\u003c/li\u003e\n\u003cli\u003eDisable the affected functionality or restrict access to the /controllers/pic.php endpoint to known administrative source IPs until a vendor patch is released.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-08T17:42:54Z","date_published":"2026-09-08T17:42:54Z","id":"https://feed.craftedsignal.io/briefs/2026-09-iwebshop-unrestricted-upload/","summary":"CVE-2026-86666 allows remote, unauthenticated attackers to perform arbitrary file uploads via the uploadFile function in iWebShop-5 versions up to 5.15.","title":"Unrestricted File Upload Vulnerability in iWebShop","url":"https://feed.craftedsignal.io/briefs/2026-09-iwebshop-unrestricted-upload/"}],"language":"en","title":"CraftedSignal Threat Feed - IWebShop-5 (\u003c= 5.15)","version":"https://jsonfeed.org/version/1.1"}