{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/nivocart/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:nivocart:nivocart:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-94104"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["NivoCart (\u003c= 2.4.0)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","rce","file-upload","cve-2026-94104"],"_cs_type":"advisory","_cs_vendors":["NivoCart"],"content_html":"\u003cp\u003eNivoCart versions 2.4.0 and earlier contain a critical arbitrary file upload vulnerability within the File Manager multi() endpoint. The application fails to validate file extensions during the upload process, particularly when the chunks parameter is set to 2 or higher. This security defect allows an attacker, even one with limited view-only back-office privileges, to bypass intended restrictions and upload malicious PHP scripts to the web-accessible image/data/ directory. Once the file is uploaded, the attacker can execute the script by directly navigating to the file path through a web browser, resulting in full remote code execution on the underlying server. This vulnerability presents a significant risk to NivoCart installations as it grants attackers the ability to compromise server-side operations and data.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains unauthorized or low-privileged access to the NivoCart back-office panel.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the File Manager component.\u003c/li\u003e\n\u003cli\u003eAttacker initiates an upload request to the multi() endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker manipulates the request to set the chunks parameter to a value of 2 or higher.\u003c/li\u003e\n\u003cli\u003eAttacker uploads a malicious PHP file, bypassing extension validation checks.\u003c/li\u003e\n\u003cli\u003eThe application saves the malicious file into the web-accessible image/data/ directory.\u003c/li\u003e\n\u003cli\u003eAttacker requests the uploaded file directly via a web browser to execute the payload.\u003c/li\u003e\n\u003cli\u003eWeb server processes the PHP code, granting the attacker remote code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unauthenticated or low-privileged attacker to achieve remote code execution on the target server. This could lead to a full system compromise, data theft, unauthorized modification of site content, and potential lateral movement within the network. All NivoCart installations at or below version 2.4.0 are affected.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately restrict access to the NivoCart back-office panel to authorized personnel only to mitigate the impact of the required low-level access.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous POST requests to the File Manager multi() endpoint, specifically tracking requests containing the chunks parameter.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering on the web server to prevent post-exploitation activity such as reverse shells or data exfiltration.\u003c/li\u003e\n\u003cli\u003ePeriodically audit the image/data/ directory for unauthorized script files (e.g., .php files) that should not be present in an image storage folder.\u003c/li\u003e\n\u003cli\u003eUpgrade NivoCart to a version beyond 2.4.0 once the vendor provides a patch to address the underlying validation flaw in the File Manager.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-20T12:21:45Z","date_published":"2026-09-20T12:21:31Z","id":"https://feed.craftedsignal.io/briefs/2026-09-nivocart-rce/","summary":"NivoCart versions 2.4.0 and earlier are vulnerable to remote code execution via an arbitrary file upload flaw in the File Manager multi() endpoint.","title":"Arbitrary File Upload Vulnerability in NivoCart File Manager","url":"https://feed.craftedsignal.io/briefs/2026-09-nivocart-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - NivoCart","version":"https://jsonfeed.org/version/1.1"}