CVE-2025-57148: Malicious File Upload
Published Sep 3, 2025
·Updated
phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the lack of extension validation.
Affected Software
2 affected components
Phpgurukul Online Shopping Portal
Phpgurukul Online Shopping Portal=2.0
Event History
Sep 3, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-57148?
CVE-2025-57148 has a high severity rating due to the potential for arbitrary file uploads.
2
How do I fix CVE-2025-57148?
To fix CVE-2025-57148, implement proper file type validation and restrict allowed file extensions for uploads.
3
What types of files can be uploaded due to CVE-2025-57148?
Due to CVE-2025-57148, any file type can potentially be uploaded, leading to serious security risks.
4
Which versions of phpgurukul Online Shopping Portal are affected by CVE-2025-57148?
CVE-2025-57148 affects phpgurukul Online Shopping Portal version 2.0.
5
What potential risks does CVE-2025-57148 pose?
CVE-2025-57148 poses risks such as server compromise, remote code execution, and unauthorized access to sensitive information.