An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated attackers can upload files with arbitrary extensions, including executable or malicious files, potentially leading to remote code execution or other security impacts depending on server configuration.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone exploit PoC consisting of two files: a README and a single Python script, exploit.py. The script targets an authenticated arbitrary file upload vulnerability in VirtueMart before version 4.4.10, identified in the repository as CVE-2025-6002. Its workflow is straightforward: it accepts a base URL and admin credentials, logs into the Joomla administrator interface, navigates to the VirtueMart product management area, extracts a CSRF token from returned HTML, creates a new product, and uploads a PHP file containing a command-execution webshell. After upload, it attempts to access the uploaded file from the public product image directory. The exploit is clearly intended for remote exploitation over HTTP and requires valid credentials, so it is not an unauthenticated RCE. The main capability implemented in code is arbitrary command execution through an uploaded PHP webshell. The payload is hardcoded as <?php system($_GET['cmd'] . ' 2>&1'); ?>. Although both the README and script comments claim the exploit invokes a reverse shell to a supplied attacker IP and port, the current implementation does not use the --remote-ip or --remote-port arguments anywhere after parsing them. Instead, get_rev_shell() simply requests the uploaded file with cmd=id, making this an operational authenticated webshell upload/command-execution PoC rather than a full reverse-shell exploit. Notable implementation details: the script only accepts base URLs beginning with http://, not https://; it uses requests.Session for cookie handling; it heuristically identifies the session cookie by looking for a cookie name of length 32 or 64; and it extracts the CSRF token using a regex for a JSON-style "csrf.token" field. There is also a commented TODO suggesting future version detection by reading /administrator/components/com_virtuemart/virtuemart.xml. Overall, the repository is purpose-built, minimal, and functional as a PoC for authenticated file upload leading to webshell-based command execution.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.