Home

Description

EN DE

A vulnerability was found in ashymuzuro Full-Ecommece-Website and Muzuro Ecommerce System up to 1.1.0. This affects an unknown part of the file /admin/index.php?add_product of the component Add Product Page. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

In ashymuzuro Full-Ecommece-Website and Muzuro Ecommerce System up to 1.1.0 ist eine Schwachstelle entdeckt worden. Das betrifft eine unbekannte Funktionalität der Datei /admin/index.php?add_product der Komponente Add Product Page. Durch das Manipulieren mit unbekannten Daten kann eine unrestricted upload-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk angegangen werden. Die Ausnutzung wurde veröffentlicht und kann verwendet werden.

PUBLISHED Reserved 2025-10-26 | Published 2025-10-27 | Updated 2025-10-30 | Assigner VulDB




MEDIUM: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
MEDIUM: 4.7CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
MEDIUM: 4.7CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
5.8AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR

Problem types

Unrestricted Upload

Improper Access Controls

Product status

1.0
affected

1.1.0
affected

1.0
affected

1.1.0
affected

Timeline

2025-10-26:Advisory disclosed
2025-10-26:VulDB entry created
2025-10-26:VulDB entry last update

Credits

lianhaorui (VulDB User) reporter

References

vuldb.com/?id.329959 (VDB-329959 | ashymuzuro Full-Ecommece-Website/Muzuro Ecommerce System Add Product index.php unrestricted upload) vdb-entry

vuldb.com/?ctiid.329959 (VDB-329959 | CTI Indicators (IOB, IOC, TTP, IOA)) signature permissions-required

vuldb.com/?submit.675846 (Submit #675846 | ashymuzuro/Full-Ecommece-Website web 1 File Upload Vulnerability) third-party-advisory

github.com/Lianhaorui/Report/blob/main/FileUpload-1.docx exploit

cve.org (CVE-2025-12291)

nvd.nist.gov (CVE-2025-12291)

Download JSON