CVE-2025-67427 | evershop up to 2.1.0 Query Parameter /images src server-side request forgery (EUVD-2026-0797)
A vulnerability classified as critical was found in evershop up to 2.1.0. Affected by this issue is some unknown functionality of the file /images of the component Query Parameter Handler. Such manipulation of the argument src leads to server-side request forgery.
This vulnerability is documented as CVE-2025-67427. The attack can be executed remotely. There is not any exploit available.