CVE-2024-31823
Ecommerce-CodeIgniter-Bootstrap Remote Code Execution via removeSecondaryImage
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A critical vulnerability exists in an e-commerce platform component that could allow a remote attacker to execute arbitrary code. This flaw is in the `removeSecondaryImage` method of the Publish.php file. Because e-commerce platforms are often publicly accessible, this issue may present a significant exposure risk.