Impact
A weakness in ShopEx ECShop up to version 2.5.1 allows an attacker to manipulate the pack_img argument in admin/pack.php, resulting in unrestricted file upload. This flaw is a classic example of improper input validation and authorization for file uploads, leading to the possibility of uploading arbitrary files. If a malicious file such as a web shell is uploaded, it could grant the attacker remote code execution, altering the confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability affects ShopEx ECShop products. Any installation of ECShop version 2.5.1 or earlier is susceptible. No specific vendor sub‑products or additional versions are listed, so the entire family bundled under the ShopEx:ECShop tag is impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity, and the lack of an EPSS score or KEV listing suggests a lower yet non‑negligible exploitation likelihood at the time of assessment. The attack vector is remote, as the vulnerable function is exposed through the web interface. Public exploit code is available, increasing the risk of real‑world attacks. The flaw can be leveraged by an unauthenticated attacker to upload files to the server, potentially leading to further compromise.
OpenCVE Enrichment