Remote Code Execution Vulnerability in Maho Ecommerce Platform
CVE-2025-58449
8.7HIGH
What is CVE-2025-58449?
Maho, an open-source ecommerce platform, prior to version 25.9.0, is susceptible to a remote code execution vulnerability. Authenticated staff users with access to the Dashboard and Catalog: Manage Products permissions can exploit the issue by uploading files with a .php extension. This oversight allows the execution of arbitrary PHP code, potentially giving attackers control over the server. Version 25.9.0 includes a fix for this vulnerability, addressing the file upload feature to enhance security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
maho < 25.9.0
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
