Medium severity5.5NVD Advisory· Published Mar 21, 2026· Updated Apr 15, 2026
CVE-2019-25577
CVE-2019-25577
Description
SeoToaster Ecommerce 3.0.0 contains a local file inclusion vulnerability that allows authenticated attackers to read arbitrary files by manipulating path parameters in backend theme endpoints. Attackers can send POST requests to /backend/backend_theme/editcss/ or /backend/backend_theme/editjs/ with directory traversal sequences in the getcss or getjs parameters to retrieve file contents.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
4- www.exploit-db.com/exploits/46190nvdExploitVDB Entry
- www.vulncheck.com/advisories/seotoaster-ecommerce-local-file-inclusion-via-backend-themenvdThird Party Advisory
- www.seotoaster.com/downloads/seotoaster.v3.0.0.zipnvdProduct
- www.seotoaster.com/shopping-cart/nvdProduct
News mentions
0No linked articles in our index yet.