PT-2025-43975 · Unknown · Ashymuzuro Full-Ecommece-Website+1
Lianhaorui
·
Published
2025-10-27
·
Updated
2025-10-28
·
CVE-2025-12291
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:L/Au:M/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ashymuzuro Full-Ecommece-Website and Muzuro Ecommerce System versions up to 1.1.0
Description
A flaw exists in the Add Product Page component of the software, specifically affecting the file
/admin/index.php?add product. This allows for unrestricted file upload, potentially enabling remote attacks. The exploit has been publicly released, and the vendor was notified but did not respond.Recommendations
Versions prior to 1.1.0 should be updated. As a temporary workaround, restrict access to the
/admin/index.php?add product endpoint.Exploit
Fix
Improper Access Control
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Muzuro Ecommerce System
Ashymuzuro Full-Ecommece-Website