


Perceptive Security
SOC/SIEM Consultancy

A weakness has been identified in ShopEx ECShop up to 2.5.1. This affects the function check_img_type of the file admin/pack.php. Executing a manipulation of th…
Published:
31 August 2026 at 00:00:00
Alert date:
1 September 2026 at 01:03:40
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
A vulnerability has been identified in ShopEx ECShop versions up to 2.5.1 involving an unrestricted file upload flaw. The vulnerability exists in the check_img_type function within the admin/pack.php file. Attackers can manipulate the pack_img argument to bypass file type restrictions and upload arbitrary files. The attack can be launched remotely without requiring physical access. A public exploit has already been released, increasing the risk of active exploitation. The vendor was notified prior to public disclosure but did not respond. This lack of vendor response leaves users without an official patch or mitigation guidance. The vulnerability poses significant risk to e-commerce platforms running affected ECShop versions.
Technical details
Mitigation steps:
Affected products:
ShopEx ECShop 2.5.1
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82921
https://uvxbywu62qm.feishu.cn/wiki/TNENwNItlitygtk2uABcj02lndc?from=from_copylink
https://vuldb.com/cve/CVE-2026-82921
https://vuldb.com/submit/879229
https://vuldb.com/vuln/397301
https://vuldb.com/vuln/397301/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
