CVE-2026-82921: ShopEx ECShop pack.php check_img_type unrestricted upload
A weakness has been identified in ShopEx ECShop up to 2.5.1. This affects the function checkimgtype of the file admin/pack.php. Executing a manipulation of the argument packimg can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
ShopEx ECShop versions up to 2.5.1 are affected where the admin/pack.php endpoint and its check_img_type function are reachable. The issue can be exploited remotely.
Does exploitation require authentication or user interaction?
The supplied vector lists no required privileges and no user interaction. An attacker can manipulate the pack_img argument to trigger the unrestricted upload condition.
Is public exploit code available?
Yes. The exploit has been made publicly available and could be used in attacks.