An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated attackers can upload files with arbitrary extensions, including executable or malicious files, potentially leading to remote code execution or other security impacts depending on server configuration.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://blog.blacklanternsecurity.com/p/doomla-zero-days |
![]() ![]() |
History
Wed, 11 Jun 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 11 Jun 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated attackers can upload files with arbitrary extensions, including executable or malicious files, potentially leading to remote code execution or other security impacts depending on server configuration. | |
Title | VirtueMart - Unrestricted File Upload | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: BLSOPS
Published: 2025-06-11T16:26:47.283Z
Updated: 2025-06-11T17:29:01.082Z
Reserved: 2025-06-11T15:56:45.306Z
Link: CVE-2025-6002

Updated: 2025-06-11T17:28:51.427Z

Status : Awaiting Analysis
Published: 2025-06-11T17:15:43.253
Modified: 2025-06-12T16:06:20.180
Link: CVE-2025-6002

No data.