top of page
perceptive_background_267k.jpg

A weakness has been identified in ShopEx ECShop up to 2.5.1. This affects the function check_img_type of the file admin/pack.php. Executing a manipulation of th…

Published:

31 August 2026 at 00:00:00

Alert date:

1 September 2026 at 01:03:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

A vulnerability has been identified in ShopEx ECShop versions up to 2.5.1 involving an unrestricted file upload flaw. The vulnerability exists in the check_img_type function within the admin/pack.php file. Attackers can manipulate the pack_img argument to bypass file type restrictions and upload arbitrary files. The attack can be launched remotely without requiring physical access. A public exploit has already been released, increasing the risk of active exploitation. The vendor was notified prior to public disclosure but did not respond. This lack of vendor response leaves users without an official patch or mitigation guidance. The vulnerability poses significant risk to e-commerce platforms running affected ECShop versions.

Technical details

Mitigation steps:

Affected products:

ShopEx ECShop 2.5.1

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page