← back
CVE-2019-16123

CVE-2019-16123

23Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 17%
exploitation probability
17%top 3% of all CVEs
observed exploitation
nono source reports it
In Kartatopia PilusCart 1.4.1, the parameter filename in the file catalog.php is mishandled, leading to ../ Local File Disclosure.
Affected products
n/a · n/a