VYPR
Vendor

Nanjing Xingyuantu Technology

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2024-40425CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in Nanjin Xingyuantu Technology Co Sparkshop (Spark Mall B2C Mall v.1.1.6 and before allows a remote attacker to execute arbitrary code via the contorller/common.php component.

  • CVE-2024-6730MedJul 14, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in Nanjing Xingyuantu Technology SparkShop up to 1.1.6. It has been rated as critical. This issue affects some unknown processing of the file /api/Common/uploadFile. The manipulation of the argument file leads to unrestricted upload. The attack may be…