In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution on the server, by uploading a crafted file and then renaming it to have a .php extension by using the Rename Function. This bypasses the initial check that uploaded files are image files. The application relies on frontend checks to restrict the administrator from changing the extension of uploaded files to .php. This restriction is easily bypassed with any proxy tool (e.g., BurpSuite). Once the attacker renames the file, and gives it the .php extension, a GET request can be used to trigger the execution of code on the server.
Metrics
Affected Vendors & Products
References
History
Mon, 23 Jun 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 23 Jun 2025 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution on the server, by uploading a crafted file and then renaming it to have a .php extension by using the Rename Function. This bypasses the initial check that uploaded files are image files. The application relies on frontend checks to restrict the administrator from changing the extension of uploaded files to .php. This restriction is easily bypassed with any proxy tool (e.g., BurpSuite). Once the attacker renames the file, and gives it the .php extension, a GET request can be used to trigger the execution of code on the server. | |
Weaknesses | CWE-420 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-06-23T00:00:00.000Z
Updated: 2025-06-23T13:51:45.551Z
Reserved: 2025-06-21T00:00:00.000Z
Link: CVE-2025-52921

Updated: 2025-06-23T13:51:42.876Z

Status : Awaiting Analysis
Published: 2025-06-23T12:15:22.970
Modified: 2025-06-23T20:16:21.633
Link: CVE-2025-52921

No data.