Vulnerabilities
Vulnerable Software
Evershop:  >> Evershop  >> 2.1.0  Security Vulnerabilities
A Denial of Service (DoS) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to exhaust the application server's resources via the "GET /images" API. The application fails to limit the height of the use-element shadow tree or the dimensions of pattern tiles during the processing of SVG files, resulting in unbounded resource consumption and system-wide denial of service.
CVSS Score
7.5
EPSS Score
0.001
Published
2026-01-05
A Blind Server-Side Request Forgery (SSRF) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to force the server to initiate an HTTP request via the "GET /images" API. The vulnerability occurs due to insufficient validation of the "src" query parameter, which permits arbitrary HTTP or HTTPS URIs, resulting in unexpected requests against internal and external networks.
CVSS Score
6.5
EPSS Score
0.0
Published
2026-01-05


Contact Us

Shodan ® - All rights reserved