Back

CRITICAL

osCommerce <= 2.2 Admin File Manager Arbitrary PHP Code Execution

Published Sep 16, 2025

Description

osCommerce versions up to and including 2.2 RC2a contain a vulnerability in its administrative file manager utility (admin/file_manager.php). The interface allows file uploads and edits without sufficient input validation or access control. An unauthenticated attacker can craft a POST request to upload a .php file containing arbitrary code, which is then executed by the server.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 16, 2025
Updated May 15, 2026
Reserved Aug 27, 2025
CISA Vulnrichment
Updated Sep 16, 2025
NVD
Status Deferred
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a