← Terug naar overzicht

A vulnerability has been identified in ShopEx ECShop versions up to 2.5.1 involving an unrestricted file upload flaw. The vulnerability exists in the check_img_type function within the admin/pack.php file. Attackers can manipulate the pack_img argument to bypass file type restrictions and upload arbitrary files. The attack can be launched remotely without requiring physical access. A public exploit has already been released, increasing the risk of active exploitation. The vendor was notified prior to public disclosure but did not respond. This lack of vendor response leaves users without an official patch or mitigation guidance. The vulnerability poses significant risk to e-commerce platforms running affected ECShop versions.

Affected products

  • ShopEx ECShop 2.5.1

Related CVE's

  • CVE-2026-82921

Categories

  • Enterprise Applications
  • Web Technologies