{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ecshop--2.5.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:shopex:ecshop:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-82921"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ECShop (\u003c= 2.5.1)"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","remote-code-execution","file-upload","web-vulnerability","sql-injection","cve-2026-82922"],"_cs_type":"advisory","_cs_vendors":["ShopEx"],"content_html":"\u003cp\u003eA vulnerability identified as CVE-2026-82921 affects ShopEx ECShop versions up to 2.5.1. The flaw exists within the check_img_type function located in the admin/pack.php script. An unauthenticated remote attacker can exploit this weakness by manipulating the pack_img parameter to bypass file type validation, allowing for the upload of arbitrary, potentially malicious files to the server. Successful exploitation of this vulnerability can lead to remote code execution (RCE) if the uploaded file is subsequently executed by the web server. Public exploit code for this vulnerability is available, and there is no indication that the vendor has addressed this issue following initial disclosure. Defenders should prioritize restricting access to the administrative directory and monitoring for suspicious file uploads.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target server running an unpatched version of ShopEx ECShop (\u0026lt;= 2.5.1).\u003c/li\u003e\n\u003cli\u003eAttacker performs reconnaissance to locate the admin/pack.php script.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious payload (e.g., a PHP web shell) embedded within an image file structure.\u003c/li\u003e\n\u003cli\u003eAttacker sends a crafted HTTP POST request to the admin/pack.php endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker manipulates the pack_img argument within the request to bypass server-side file type checks in check_img_type.\u003c/li\u003e\n\u003cli\u003eThe server saves the malicious file to the web root or an accessible upload directory.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the uploaded file's URL to trigger code execution on the server.\u003c/li\u003e\n\u003cli\u003eAttacker establishes persistent access or begins data exfiltration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary file uploads, which provides a direct path for remote code execution. This can result in complete system compromise, unauthorized data access, and lateral movement within the network. Sectors relying on ECShop for e-commerce operations are at high risk of site defacement, financial data theft, and loss of customer information.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection engineering and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement strict ingress filtering for the /admin/ directory to ensure it is not reachable from the public internet.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect suspicious HTTP requests targeting the admin/pack.php script.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous POST requests to admin/pack.php that contain unexpected file extensions or script contents.\u003c/li\u003e\n\u003cli\u003eConfigure file integrity monitoring on the web server's document root to alert on the creation of new executable files in upload directories.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T01:01:51Z","date_published":"2026-09-01T01:01:41Z","id":"https://feed.craftedsignal.io/briefs/2026-09-shopex-ecshop-upload/","summary":"ShopEx ECShop versions up to 2.5.1 contain an unrestricted file upload vulnerability in the check_img_type function that allows unauthenticated remote attackers to upload malicious files via the pack_img argument.","title":"Unrestricted File Upload Vulnerability in ShopEx ECShop","url":"https://feed.craftedsignal.io/briefs/2026-09-shopex-ecshop-upload/"}],"language":"en","title":"CraftedSignal Threat Feed - ECShop (\u003c= 2.5.1)","version":"https://jsonfeed.org/version/1.1"}