Логотип exploitDog
bind:CVE-2025-65844
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-65844

Количество 2

Количество 2

nvd логотип

CVE-2025-65844

2 месяца назад

EverShop 2.0.1 allows a remote unauthenticated attacker to upload arbitrary files and create directories via the /api/images endpoint. The endpoint is accessible without authentication by default, and server-side validation of uploaded files is insufficient. This can be abused to upload arbitrary content (including non-image files) which could impersonate user/admin login panels (exfiltrating credentials) and to perform a denial-of-service attack by exhausting disk space.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-c88j-gfxj-293x

2 месяца назад

EverShop 2.0.1 allows an unauthenticated user to upload files and create directories within the /api/images endpoint.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-65844

EverShop 2.0.1 allows a remote unauthenticated attacker to upload arbitrary files and create directories via the /api/images endpoint. The endpoint is accessible without authentication by default, and server-side validation of uploaded files is insufficient. This can be abused to upload arbitrary content (including non-image files) which could impersonate user/admin login panels (exfiltrating credentials) and to perform a denial-of-service attack by exhausting disk space.

CVSS3: 7.5
0%
Низкий
2 месяца назад
github логотип
GHSA-c88j-gfxj-293x

EverShop 2.0.1 allows an unauthenticated user to upload files and create directories within the /api/images endpoint.

CVSS3: 7.5
0%
Низкий
2 месяца назад

Уязвимостей на страницу