← Vulnerability feed

Vulnerability record · CVE-2024-0352 · published 9 January 2024

CVE-2024-0352: Likeshop FileServer::userFormImage unrestricted file upload

Likeshop · Likeshop

Likeshop up to 2.5.7.20210311 contains an unrestricted file upload in FileServer::userFormImage in server/application/api/controller/File.php, reachable via HTTP POST. The file argument is not properly validated, allowing an attacker to upload arbitrary files. Because the endpoint is remotely reachable without authentication, this is a critical risk for code execution or server compromise.

9.8 CVSS 3.1 Critical EPSS 73% · top 0.6% CWE-434 · Unrestricted file upload
9.8CVSS 3.1 base score, v2 7.5
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A vulnerability classified as critical was found in Likeshop up to 2.5.7.20210311. This vulnerability affects the function FileServer::userFormImage of the file server/application/api/controller/File.php of the component HTTP POST Request Handler. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250120.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication, no user interaction, and public exploit disclosure make this a critical risk.

What it is

Likeshop up to 2.5.7.20210311 contains an unrestricted file upload in FileServer::userFormImage in server/application/api/controller/File.php, reachable via HTTP POST. The file argument is not properly validated, allowing an attacker to upload arbitrary files. Because the endpoint is remotely reachable without authentication, this is a critical risk for code execution or server compromise.

Impact

An attacker can upload arbitrary files, including executable scripts, to the server. Successful exploitation can lead to remote code execution, full server compromise, and data theft or modification.

Attack surface

The flaw is reached over the network via an HTTP POST request to the File API endpoint handling userFormImage. The CVSS vector indicates no authentication (PR:N) and no user interaction (UI:N) are required.

Exploitation

The description states the exploit has been disclosed publicly and may be used. CISA KEV does not list this CVE, but EPSS is very high at 0.72917 (99.4th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Apply the vendor patch or upgrade Likeshop beyond 2.5.7.20210311 if an official fix is available.
  • Restrict upload handling to allowlisted file types and validate file content, not just extensions.
  • Disable execution of uploaded files by storing them outside the web root or configuring the web server to deny script execution in upload directories.
  • Require authentication and authorization for the File API endpoint if it is not intended to be public.
  • Monitor and block POST requests to the vulnerable File.php endpoint until patching is complete.

Detection

  • Search web server logs for POST requests to server/application/api/controller/File.php or the userFormImage action, especially with multipart/form-data uploads.
  • Monitor upload directories for newly created executable files (e.g., .php, .phtml, .jsp) and alert on unexpected file types.
  • Use file integrity monitoring to detect new or modified files in web-accessible directories.
  • Inspect HTTP traffic for anomalous file uploads with suspicious filenames or content types.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://note.zhaoj.in/share/ciwYj7QXC4sZ Broken Link
https://vuldb.com/?ctiid.250120 Permissions RequiredThird Party Advisory
https://vuldb.com/?id.250120 Third Party Advisory
https://note.zhaoj.in/share/ciwYj7QXC4sZ Broken Link
https://vuldb.com/?ctiid.250120 Permissions RequiredThird Party Advisory
https://vuldb.com/?id.250120 Third Party Advisory

Track CVE-2024-0352 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.2CVE-2024-34949Likeshop sql injection vulnerabilitySQL injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function OrderLogic::getOrderList function…EPSS 0.42%7.2CVE-2024-24027Likeshop sql injection vulnerabilitySQL Injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function DistributionMemberLogic::getFansL…EPSS 0.67%5.9CVE-2024-24028Likeshop server-side request forgery (ssrf) vulnerabilityServer Side Request Forgery (SSRF) vulnerability in Likeshop before 2.5.7 allows attackers to view sensitive information via the avatar parameter in …EPSS 0.22%5.3CVE-2024-41432Likeshop authentication bypass by spoofing vulnerabilityAn IP Spoofing vulnerability has been discovered in Likeshop up to 2.5.7.20210811. This issue allows an attacker to replace their real IP address wit…EPSS 0.38%5.1CVE-2024-5766Likeshop cross-site scripting vulnerabilityA vulnerability was found in Likeshop up to 2.5.7 and classified as problematic. This issue affects some unknown processing of the file /admin of the…EPSS 0.35%10.0CVE-2026-56291Balbooa Forms Joomla extension unauthenticated arbitrary file upload RCEThe Balbooa Forms extension for Joomla before version 2.4.1 accepts file uploads without authentication and does not restrict file type, allowing exe…KEVEPSS 15%analysed10.0CVE-2026-48939iCagenda Joomla extension unrestricted file upload leads to PHP RCEThe iCagenda extension for Joomla fails to restrict file types in its file attachment feature, allowing arbitrary file uploads that result in PHP cod…KEVEPSS 20%analysed10.0CVE-2026-56290Joomla Page Builder CK unauthenticated file upload leads to RCEThe Joomla Page Builder CK extension before 3.6.0 allows unauthenticated arbitrary file uploads, letting an attacker place executable files on the se…KEVEPSS 31%analysed

Source: NIST National Vulnerability Database (record CVE-2024-0352), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.