Unrestricted File Upload Vulnerability in VirtueMart Backend
CVE-2025-6002

7.2HIGH

Key Information:

Vendor

Virtuemart

Vendor
CVE Published:
11 June 2025

What is CVE-2025-6002?

An unrestricted file upload vulnerability in the Product Image section of the VirtueMart backend allows authenticated attackers to upload files with arbitrary extensions. This could include executable or malicious files, posing a significant risk of remote code execution or other security issues, depending on server configuration. It is vital for users to review their systems and apply necessary patches or configurations to mitigate potential exploitation.

Affected Version(s)

VirtueMart Windows 3.0.0 < 4.4.10

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-6002 : Unrestricted File Upload Vulnerability in VirtueMart Backend