{"id":72445,"date":"2025-10-27T19:45:38","date_gmt":"2025-10-27T16:15:38","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2025-12291-ashymuzuro-full-ecommece-website-muzuro-ecommerce-system-add-product-index-php-unrestricted-upload\/"},"modified":"2025-10-27T19:45:38","modified_gmt":"2025-10-27T16:15:38","slug":"cve-2025-12291-ashymuzuro-full-ecommece-website-muzuro-ecommerce-system-add-product-index-php-unrestricted-upload","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2025-12291-ashymuzuro-full-ecommece-website-muzuro-ecommerce-system-add-product-index-php-unrestricted-upload\/","title":{"rendered":"CVE-2025-12291 &#8211; ashymuzuro Full-Ecommece-Website\/Muzuro Ecommerce System Add Product index.php unrestricted upload"},"content":{"rendered":"<p>CVE ID : CVE-2025-12291<\/p>\n<p>Published :  Oct. 27, 2025, 4:15 p.m. | 29\u00a0minutes ago<\/p>\n<p>Description : A vulnerability was found in ashymuzuro Full-Ecommece-Website and Muzuro Ecommerce System up to 1.1.0. This affects an unknown part of the file \/admin\/index.php?add_product of the component Add Product Page. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.<\/p>\n<p>Severity: 5.8 | MEDIUM<\/p>\n<p>Visit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID : CVE-2025-12291 Published : Oct. 27, 2025, 4:15 p.m. | 29\u00a0minutes ago Description : A vulnerability was found in ashymuzuro Full-Ecommece-Website and Muzuro Ecommerce System up to 1.1.0. This affects an unknown part of the file \/admin\/index.php?add_product of the component Add Product Page. The manipulation results in unrestricted upload. The attack may be &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-72445","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/72445","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=72445"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/72445\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=72445"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=72445"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=72445"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}