PT-2025-53667 · Unknown · H-Moses Moga-Mall

Zyhsec

·

Published

2025-12-28

·

Updated

2025-12-28

·

CVE-2025-15152

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions h-moses moga-mall versions prior to 392d631a5ef15962a9bddeeb9f1269b9085473fa
Description A vulnerability exists in h-moses moga-mall. The issue affects the addProduct function within the file src/main/java/com/ms/product/controller/PmsProductController.java, allowing for unrestricted file upload through manipulation of the objectName argument. This attack can be performed remotely. The product uses a rolling release system, and version information for affected or updated releases is not disclosed.
Recommendations Versions prior to 392d631a5ef15962a9bddeeb9f1269b9085473fa should be updated. As a temporary workaround, consider restricting access to the addProduct function until a suitable update is available.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-15152

Affected Products

H-Moses Moga-Mall