High severity8.8OSV Advisory· Published Aug 16, 2018· Updated Jun 17, 2026
CVE-2018-12256
CVE-2018-12256
Description
admin/vqmods.app/vqmods.inc.php in LiteCart before 2.1.3 allows remote authenticated attackers to upload a malicious file (resulting in remote code execution) by using the text/xml or application/xml Content-Type in a public_html/admin/?app=vqmods&doc=vqmods request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- github.com/litecart/litecart/commit/2305368eb70a26cab34c772c9ae88787f4c3e669nvdPatchThird Party Advisory
- www.litecart.net/downloadnvdVendor Advisory
News mentions
0No linked articles in our index yet.