CVE-2025-6002

HIGH

VirtueMart - Unrestricted File Upload

Title source: llm

Description

An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated attackers can upload files with arbitrary extensions, including executable or malicious files, potentially leading to remote code execution or other security impacts depending on server configuration.

Exploits (1)

nomisec WORKING POC
by schn1tzelme1ster · poc
https://github.com/schn1tzelme1ster/CVE-2025-6002

Scores

CVSS v3 7.2
EPSS 0.0152
EPSS Percentile 81.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
VirtueMart/VirtueMart 3.0.0 - 4.4.10
Published Jun 11, 2025
Tracked Since Feb 18, 2026