Cyber Posture

CVE-2025-26325

CriticalPublic PoC

Published: 27 February 2025

Published
27 February 2025
Modified
10 April 2025
KEV Added
Patch
CVSS Score 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0019 40.5th percentile
Risk Priority 20 60% EPSS · 20% KEV · 20% CVSS

Description

ShopXO 6.4.0 is vulnerable to File Upload in ThemeDataService.php.

Security Summary

CVE-2025-26325 affects ShopXO version 6.4.0 and involves an unrestricted file upload vulnerability in the ThemeDataService.php component. Classified under CWE-434 (Unrestricted Upload of File with Dangerous Type), it carries a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), highlighting its critical severity due to network-based access, low complexity, lack of authentication or user interaction requirements, and high potential impacts across confidentiality, integrity, and availability. The vulnerability was published on 2025-02-27.

Unauthenticated remote attackers can exploit this flaw over the network without privileges or user interaction. By uploading malicious files through the vulnerable ThemeDataService.php endpoint, attackers can achieve high-impact outcomes, including potential remote code execution, data compromise, or system disruption, as indicated by the CVSS metrics.

The issue is documented in GitHub issue #86 on the gongfuxiang/shopxo repository (https://github.com/gongfuxiang/shopxo/issues/86), where security practitioners should review for any disclosed patches, workarounds, or mitigation guidance.

Details

CWE(s)
CWE-434

Affected Products

shopxo
shopxo
6.4.0

References