PT-2026-1329 · Evershop · Evershop

Published

2026-01-05

·

Updated

2026-01-06

·

CVE-2025-67427

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions evershop versions prior to 2.1.1
Description A Blind Server-Side Request Forgery (SSRF) exists in evershop versions prior to 2.1.1. An unauthenticated attacker can force the server to initiate an HTTP request via the ''/images'' API endpoint. This is due to insufficient validation of the src query parameter, allowing arbitrary HTTP or HTTPS URIs to be used, potentially leading to requests against internal and external networks.
Recommendations Update evershop to version 2.1.1 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-67427
GHSA-VP8W-WJ4M-3R7J

Affected Products

Evershop