Product
ShopXO versions up to 2.2.7 are vulnerable to remote path traversal attacks via the path_type argument in the Ueditor Upload Interface, allowing unauthorized file access.