top of page
perceptive_background_267k.jpg

A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary files to any writeable path via a crafted…

Published:

29 April 2026 at 22:00:00

Alert date:

30 April 2026 at 19:02:01

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

A path traversal vulnerability has been identified in shopizer v3.2.5, specifically in the /content/images/add endpoint. This security flaw allows attackers to write arbitrary files to any writable path on the system through crafted POST requests. The vulnerability enables unauthorized file upload and potential system compromise by bypassing normal file path restrictions. Attackers can exploit this weakness to upload malicious files to sensitive directories, potentially leading to remote code execution or data manipulation. The issue affects the popular open-source e-commerce platform shopizer and has been documented in the project's GitHub repository.

Technical details

Mitigation steps:

Affected products:

shopizer

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page