CVE Details
Basic Information
| Title | VirtueMart – Unrestricted File Upload |
|---|---|
| Type | cve |
| Published | 2025-06-11T16:26:47.283Z |
| Last Seen |
Product Information
| Vendor | VirtueMart |
|---|---|
| Product | VirtueMart |
| Version | 3.0.0 |
CVSS Information
| Base Score | 7.2 (HIGH) |
|---|---|
| Attack Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | An unrestricted file upload vulnerability in VirtueMart’s backend allows authenticated attackers to upload malicious files, potentially leading to remote code execution. This could severely impact server security if exploited. |
|---|---|
| AI Severity | High |
| Vendor | VirtueMart Project |
| Product | VirtueMart |
| Affected Version | 3.0.0 |
Affected Products
- VirtueMart VirtueMart 3.0.0
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-434 |
| Bulletin Family |
Description
An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated attackers can upload files with arbitrary extensions, including executable or malicious files, potentially leading to remote code execution or other security impacts depending on server configuration.