PT-2025-48242 · Evershop · Evershop

Published

2025-11-27

·

Updated

2025-12-06

·

CVE-2025-65844

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions EverShop version 2.0.1
Description An unauthenticated user can upload files and create directories using the /api/images endpoint.
Recommendations Restrict access to the /api/images endpoint to authenticated users only.

Fix

DoS

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-65844

Affected Products

Evershop