<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Aircheng-Org - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/aircheng-org/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 08 Sep 2026 17:42:54 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/aircheng-org/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unrestricted File Upload Vulnerability in iWebShop</title><link>https://feed.craftedsignal.io/briefs/2026-09-iwebshop-unrestricted-upload/</link><pubDate>Tue, 08 Sep 2026 17:42:54 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-iwebshop-unrestricted-upload/</guid><description>CVE-2026-86666 allows remote, unauthenticated attackers to perform arbitrary file uploads via the uploadFile function in iWebShop-5 versions up to 5.15.</description><content:encoded><![CDATA[<p>A high-severity unrestricted file upload vulnerability, identified as CVE-2026-86666, exists in iWebShop-5 versions up to 5.15. The vulnerability is located within the uploadFile function of the controllers/pic.php file. Remote attackers can leverage this flaw to upload malicious files, such as web shells, to the web server, potentially leading to remote code execution. Public exploit code for this vulnerability is currently available, and the vendor has not yet addressed the issue. Organizations using iWebShop-5 are at risk of compromise and should restrict access to the affected upload functionality until a security patch is provided.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows for remote file upload, which is a precursor to full system compromise or web defacement. Because the exploit is publicly available, the risk of automated or targeted exploitation is elevated. Organizations hosting e-commerce platforms using the affected versions of iWebShop are highly susceptible to malicious file drops and subsequent code execution.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Implement request filtering at the web application firewall (WAF) to inspect POST requests directed to /controllers/pic.php for suspicious file extensions or content types.</li>
<li>Monitor web server access logs for anomalous requests to the uploadFile function.</li>
<li>Disable the affected functionality or restrict access to the /controllers/pic.php endpoint to known administrative source IPs until a vendor patch is released.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>file-upload</category><category>vulnerability</category></item></channel></rss>