PT-2026-1329 · Evershop · Evershop
Published
2026-01-05
·
Updated
2026-01-06
·
CVE-2025-67427
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
evershop versions prior to 2.1.1
Description
A Blind Server-Side Request Forgery (SSRF) exists in evershop versions prior to 2.1.1. An unauthenticated attacker can force the server to initiate an HTTP request via the ''/images'' API endpoint. This is due to insufficient validation of the
src query parameter, allowing arbitrary HTTP or HTTPS URIs to be used, potentially leading to requests against internal and external networks.Recommendations
Update evershop to version 2.1.1 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Evershop