An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated attackers can upload files with arbitrary extensions, including executable or malicious files, potentially leading to remote code execution or other security impacts depending on server configuration.
References
Link | Resource |
---|---|
https://blog.blacklanternsecurity.com/p/doomla-zero-days |
Configurations
No configuration.
History
12 Jun 2025, 16:06
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
11 Jun 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-11 17:15
Updated : 2025-06-12 16:06
NVD link : CVE-2025-6002
Mitre link : CVE-2025-6002
CVE.ORG link : CVE-2025-6002
JSON object : View
Products Affected
No product.
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type