Filtered by vendor Ec-cube
                         Subscriptions
                    
                    
                
                        Filtered by product Product Image Bulk Upload
                         Subscriptions
                    
                    
                
                    Total
                    1 CVE
                
            | CVE | Vendors | Products | Updated | CVSS v3.1 | 
|---|---|---|---|---|
| CVE-2022-37346 | 1 Ec-cube | 1 Product Image Bulk Upload | 2025-05-21 | 9.8 Critical | 
| EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files. Exploiting this vulnerability allows a remote unauthenticated attacker to upload arbitrary files other than image files. If a user with an administrative privilege of EC-CUBE where the vulnerable plugin is installed is led to upload a specially crafted file, an arbitrary script may be executed on the system. | ||||
                            
                                
                                
                                    Page 1 of 1.