6.3
CVSSv3

CVE-2025-3558

CVSSv4: 5.3 | CVSSv3: 6.3 | CVSSv2: 6.5 | VMScore: 630 | EPSS: 0.00038 | KEV: Not Included
Published: 14/04/2025 Updated: 15/04/2025

Vulnerability Summary

Unrestricted File Upload Vulnerability in Ghostxbh Uzy-SSM-Mall 1.0.0

A critical vulnerability exists in ghostxbh uzy-ssm-mall version 1.0.0. The vulnerability is located in the /mall/user/uploadUserHeadImage file and involves an unrestricted file upload issue through manipulation of the File argument. An attacker can initiate this vulnerability remotely. The exploit details have been publicly disclosed, and the potential for active exploitation exists. Despite early notification, the vendor did not provide a response to address the security issue.

Vulnerable Product Search on Vulmon Subscribe to Product

ghostxbh uzy-ssm-mall