CVE-2025-58449 | MahoCommerce maho up to 25.8.x PHP File Parser reliance on file name or extension of externally-supplied file (GHSA-vgmm-27fc-vmgp)
A vulnerability was found in MahoCommerce maho up to 25.8.x. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component PHP File Parser. This manipulation causes reliance on file name or extension of externally-supplied file.
This vulnerability is registered as CVE-2025-58449. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.