Description
Maho is a free and open source ecommerce platform. In Maho prior to 25.9.0, an authenticated staff user with access to the `Dashboard` and `Catalog\Manage Products` permissions can create a custom option on a listing with a file input field. By allowing file uploads with a `.php` extension, the user can use the filed to upload malicious PHP files, gaining remote code execution. Version 25.9.0 fixes the issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27272 | Maho is a free and open source ecommerce platform. In Maho prior to 25.9.0, an authenticated staff user with access to the `Dashboard` and `Catalog\Manage Products` permissions can create a custom option on a listing with a file input field. By allowing file uploads with a `.php` extension, the user can use the filed to upload malicious PHP files, gaining remote code execution. Version 25.9.0 fixes the issue. |
Github GHSA |
GHSA-vgmm-27fc-vmgp | Maho is Vulnerable to Authenticated Remote Code Execution via File Upload |
References
History
Tue, 09 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Sep 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Maho is a free and open source ecommerce platform. In Maho prior to 25.9.0, an authenticated staff user with access to the `Dashboard` and `Catalog\Manage Products` permissions can create a custom option on a listing with a file input field. By allowing file uploads with a `.php` extension, the user can use the filed to upload malicious PHP files, gaining remote code execution. Version 25.9.0 fixes the issue. | |
| Title | Maho Vulnerable to Authenticated Remote Code Execution via File Upload | |
| Weaknesses | CWE-646 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-09T13:30:56.695Z
Reserved: 2025-09-01T20:03:06.533Z
Link: CVE-2025-58449
Updated: 2025-09-09T13:16:29.247Z
Status : Deferred
Published: 2025-09-08T22:15:34.423
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-58449
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA