{"id":"CVE-2024-6524","aliases":["GHSA-c96r-38gv-grp4"],"url":"https://o3.security/vulnerability/CVE-2024-6524","summary":"ShopXO Uploader.php server-side request forgery","details":"A vulnerability was found in ShopXO up to 6.1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file extend/base/Uploader.php. The manipulation of the argument source leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-270367. NOTE: The original disclosure confuses CSRF with SSRF.","published":"2024-07-05T12:00:06.218Z","modified":"2026-08-12T03:51:31.941947850Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"shopxo/shopxo","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/6xxx/CVE-2024-6524.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-6524"},{"type":"ADVISORY","url":"https://vuldb.com/?id.270367"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.365173"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.270367"},{"type":"EVIDENCE","url":"https://github.com/J1rrY-learn/learn/blob/main/shopxo_ssrf.md"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:31.941947850Z"}}