VirtueMart – Unrestricted File Upload

CVE Details

Basic Information

Title VirtueMart – Unrestricted File Upload
Type cve
Published 2025-06-11T16:26:47.283Z
Last Seen

Product Information

Vendor VirtueMart
Product VirtueMart
Version 3.0.0

CVSS Information

Base Score 7.2 (HIGH)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description An unrestricted file upload vulnerability in VirtueMart’s backend allows authenticated attackers to upload malicious files, potentially leading to remote code execution. This could severely impact server security if exploited.
AI Severity High
Vendor VirtueMart Project
Product VirtueMart
Affected Version 3.0.0

Affected Products

  • VirtueMart VirtueMart 3.0.0

Additional Information

CVE List
CWE List CWE-434
Bulletin Family

Description

An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated attackers can upload files with arbitrary extensions, including executable or malicious files, potentially leading to remote code execution or other security impacts depending on server configuration.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.