A File Deletion vulnerability exists in TinyShop 3.1.1 in the back_list parameter in controllersadmin.php, which could let a malicious user delete any file such as install.lock to reinstall cms.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Tinyshop | Tinyrise | 3.1.1 (including) | 3.1.1 (including) |