An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated attackers can upload files with arbitrary extensions, including executable or malicious files, potentially leading to remote code execution or other security impacts depending on server configuration.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://blog.blacklanternsecurity.com/p/doomla-zero-days |
|
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 11 Jun 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Jun 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated attackers can upload files with arbitrary extensions, including executable or malicious files, potentially leading to remote code execution or other security impacts depending on server configuration. | |
| Title | VirtueMart - Unrestricted File Upload | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: BLSOPS
Published: 2025-06-11T16:26:47.283Z
Updated: 2025-06-11T17:29:01.082Z
Reserved: 2025-06-11T15:56:45.306Z
Link: CVE-2025-6002
Updated: 2025-06-11T17:28:51.427Z
Status : Awaiting Analysis
Published: 2025-06-11T17:15:43.253
Modified: 2025-06-12T16:06:20.180
Link: CVE-2025-6002
No data.