"value":"A vulnerability, which was classified as critical, has been found in Juanpao JPShop up to 1.5.02. This issue affects the function actionUpdate of the file /api/controllers/merchant/design/MaterialController.php of the component API. The manipulation of the argument pic_url leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-253001 was assigned to this vulnerability."
"value":"Una vulnerabilidad fue encontrada en Juanpao JPShop hasta 1.5.02 y clasificada como cr\u00edtica. Este problema afecta la funci\u00f3n actionUpdate del archivo /api/controllers/merchant/design/MaterialController.php del componente API. La manipulaci\u00f3n del argumento pic_url conduce a una carga sin restricciones. El ataque puede iniciarse de forma remota. El exploit ha sido divulgado al p\u00fablico y puede utilizarse. A esta vulnerabilidad se le asign\u00f3 el identificador VDB-253001."