PT-2025-53667 · Unknown · H-Moses Moga-Mall
Zyhsec
·
Published
2025-12-28
·
Updated
2025-12-28
·
CVE-2025-15152
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
h-moses moga-mall versions prior to 392d631a5ef15962a9bddeeb9f1269b9085473fa
Description
A vulnerability exists in h-moses moga-mall. The issue affects the
addProduct function within the file src/main/java/com/ms/product/controller/PmsProductController.java, allowing for unrestricted file upload through manipulation of the objectName argument. This attack can be performed remotely. The product uses a rolling release system, and version information for affected or updated releases is not disclosed.Recommendations
Versions prior to 392d631a5ef15962a9bddeeb9f1269b9085473fa should be updated. As a temporary workaround, consider restricting access to the
addProduct function until a suitable update is available.Exploit
Fix
Improper Access Control
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
H-Moses Moga-Mall