CVE-2025-58449

Maho is a free and open source ecommerce platform. In Maho prior to 25.9.0, an authenticated staff user with access to the `Dashboard` and `Catalog\Manage Products` permissions can create a custom option on a listing with a file input field. By allowing file uploads with a `.php` extension, the user can use the filed to upload malicious PHP files, gaining remote code execution. Version 25.9.0 fixes the issue.
CVSS

No CVSS.

Configurations

No configuration.

History

09 Sep 2025, 14:15

Type Values Removed Values Added
References () https://github.com/MahoCommerce/maho/security/advisories/GHSA-vgmm-27fc-vmgp - () https://github.com/MahoCommerce/maho/security/advisories/GHSA-vgmm-27fc-vmgp -

08 Sep 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-08 22:15

Updated : 2025-09-09 16:28


NVD link : CVE-2025-58449

Mitre link : CVE-2025-58449

CVE.ORG link : CVE-2025-58449


JSON object : View

Products Affected

No product.

CWE
CWE-646

Reliance on File Name or Extension of Externally-Supplied File