{"id":"CVE-2025-58449","summary":"Maho Vulnerable to Authenticated Remote Code Execution via File Upload","details":"Maho is a free and open source ecommerce platform. In Maho prior to 25.9.0, an authenticated staff user with access to the `Dashboard` and `Catalog\\Manage Products` permissions can create a custom option on a listing with a file input field. By allowing file uploads with a `.php` extension, the user can use the filed to upload malicious PHP files, gaining remote code execution. Version 25.9.0 fixes the issue.","aliases":["GHSA-vgmm-27fc-vmgp"],"modified":"2026-08-12T03:51:38.545096746Z","published":"2025-09-08T21:27:55.103Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58449.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-646"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58449.json"},{"type":"ADVISORY","url":"https://github.com/MahoCommerce/maho/security/advisories/GHSA-vgmm-27fc-vmgp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58449"},{"type":"FIX","url":"https://github.com/MahoCommerce/maho/commit/db54a1b44e9b3fd26b27ca4d5ece0af99c4dcb53"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mahocommerce/maho","events":[{"introduced":"0"},{"fixed":"db54a1b44e9b3fd26b27ca4d5ece0af99c4dcb53"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"25.9.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["25.7.0","25.5.0","25.3.0","25.1.0","24.11.0","24.9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-58449.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}]}