S4E just found a high-severity finding from cve-2025-58360 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 25, 2024

CVE-2024-0352 Scanner

CVE-2024-0352 scanner - Arbitrary File Upload vulnerability in Likeshop

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-0352
9.8
CVSShigh
Exploitable remotely over the internet · no authentication required.

A vulnerability classified as critical was found in Likeshop up to 2.5.7.20210311. This vulnerability affects the function FileServer::userFormImage of the file server/application/api/controller/File.php of the component HTTP POST Request Handler. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250120.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Likeshopby n/a
2.5.7.20210311
Updated Aug 22, 2026View on NVD →
Detail

Likeshop is an e-commerce platform used for building social media stores. It is specifically designed for the popular social media platform, Facebook. Sellers can use Likeshop to list and sell their products on their Facebook pages. This platform is ideal for small businesses, entrepreneurs, and aspiring online merchants who want to establish their presence on social media.

The vulnerability code CVE-2024-0352 was detected in Likeshop up to version 2.5.7.20210311. This vulnerability affects the function FileServer::userFormImage of the file server/application/api/controller/File.php of the component HTTP POST Request Handler. A skilled attacker can exploit this vulnerability remotely by manipulating the file argument and gain unrestricted access to upload files. This is a critical vulnerability as it allows an attacker to execute arbitrary code on the server and gain complete control over the system.

Exploiting this vulnerability can lead to severe consequences for the seller, customers, and the business as a whole. An attacker can upload malicious files that can infect the operating system and compromise the entire server. The attacker can easily steal user data, including personal and financial information. This can result in identity theft, fraud, and financial losses. It can also lead to a loss of reputation for the seller and the business, which can be challenging to recover from.

By subscribing to s4e.io Pro services, readers can easily and quickly learn about vulnerabilities in their digital assets. The platform offers advanced features to detect, prevent and respond to cyber threats. The platform can scan for vulnerabilities, provide real-time alerts, and offer actionable insights to mitigate risks. Businesses can protect their digital assets with personalized protection plans tailored to their specific needs. The s4e.io platform is a reliable and effective solution for businesses of all sizes to protect their digital assets from potential cyber threats.

 

REFERENCES

Solution Advice

There are several precautions that can be taken to protect against this vulnerability. Some of these precautions include:

  • Disabling file upload functionality until a patch is released.
  • Implementing strict input validation to prevent malicious file upload attempts.
  • Regularly monitoring and auditing file uploads to ensure they are legitimate.
  • Installing updates and patches as they become available.
  • Implementing network segmentation to limit the damage an attacker can cause if they exploit the vulnerability.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.