Bluestar Micro Mall Unrestricted File Upload Vulnerability

Vulnerability

A critical vulnerability allowing unrestricted file uploads has been identified in Bluestar Micro Mall version 1.0. The issue arises in the file '/api/api.php?mod=upload&type=1', where the 'File' argument can be manipulated to upload potentially dangerous files. This vulnerability can be exploited remotely, and details of the exploit have been made public.

Impact

Exploitation of this vulnerability could lead to arbitrary file upload, allowing attackers to upload malicious files that could be executed or processed by the application.

Reproduction

The vulnerability can be reproduced by sending a request to '/api/api.php?mod=upload&type=1' with a manipulated 'File' argument that bypasses any file type restrictions. This can be done using a variety of tools that allow for HTTP request manipulation, such as Postman or curl.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.