CVE-2025-0460: Blog Botz for Journal Theme blog_add unrestricted upload
A vulnerability, which was classified as critical, was found in Blog Botz for Journal Theme 1.0 on OpenCart. This affects an unknown part of the file /index.php?route=extension/module/blogadd. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0460?
CVE-2025-0460 is classified as a critical vulnerability.
How do I fix CVE-2025-0460?
Fixing CVE-2025-0460 involves updating the Blog Botz for Journal Theme to the latest version that addresses this vulnerability.
What does CVE-2025-0460 affect?
CVE-2025-0460 affects the OpenCart Blog Botz for Journal Theme on file /index.php?route=extension/module/blog_add.
What type of vulnerability is CVE-2025-0460?
CVE-2025-0460 is an unrestricted file upload vulnerability that allows manipulation of the argument image.
Can CVE-2025-0460 be exploited?
Yes, CVE-2025-0460 can be exploited to execute arbitrary code on the server due to unrestricted file upload capabilities.