Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 31 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in ShopEx ECShop up to 2.5.1. This affects the function check_img_type of the file admin/pack.php. Executing a manipulation of the argument pack_img can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | ShopEx ECShop pack.php check_img_type unrestricted upload | |
| First Time appeared |
Shopex
Shopex ecshop |
|
| Weaknesses | CWE-284 CWE-434 |
|
| CPEs | cpe:2.3:a:shopex:ecshop:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Shopex
Shopex ecshop |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-31T21:15:35.351Z
Reserved: 2026-08-31T11:34:33.389Z
Link: CVE-2026-82921
No data.
Status : Received
Published: 2026-08-31T22:17:33.740
Modified: 2026-08-31T22:17:33.740
Link: CVE-2026-82921
No data.
OpenCVE Enrichment
No data.