PT-2025-25228 · Unknown · Virtuemart

Jack Pas

·

Published

2025-06-11

·

Updated

2025-06-11

·

CVE-2025-6001

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions VirtueMart (affected versions not specified)
Description A Cross-Site Request Forgery (CSRF) issue exists in the product image upload function of VirtueMart, allowing an attacker to bypass the CSRF protection token. This enables the attacker to craft a special CSRF request for unrestricted file upload into the VirtueMart media manager.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-6001

Affected Products

Virtuemart