CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.3. See the original NVD description below for full technical details.
CVE
CVE-2025-6001
Severity
HIGH
CVSS
8.3
EPSS
0.20%
Original NVD Description
A Cross-Site Request Forgery (CSRF) vulnerability exists in the product image upload function of VirtueMart that bypasses the CSRF protection token. An attacker is able to craft a special CSRF request which will allow unrestricted file upload into the VirtueMart media manager.