Unrestricted File Upload in ShopEx ECShop Affects Remote Operations
CVE-2026-82921
Key Information:
Badges
What is CVE-2026-82921?
A vulnerability exists within ShopEx ECShop versions up to 2.5.1 in the check_img_type functionality located in admin/pack.php. Specifically, this weakness allows an attacker to manipulate the pack_img argument, resulting in unrestricted file uploads. This flaw exposes affected systems to potential remote exploitation, as the attack vector is publicly available. Despite proactive outreach to the vendor for remediation, no response has been noted.
Affected Version(s)
ECShop 2.5.0
ECShop 2.5.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
