Логотип exploitDog
bind:CVE-2025-11136
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-11136

Количество 2

Количество 2

nvd логотип

CVE-2025-11136

4 месяца назад

A flaw has been found in YiFang CMS up to 2.0.2. The impacted element is the function webUploader of the file app/app/controller/File.php of the component Backend. Executing manipulation of the argument uploadpath can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published and may be used.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-32xq-c7f5-x98h

4 месяца назад

A flaw has been found in YiFang CMS up to 2.0.2. The impacted element is the function webUploader of the file app/app/controller/File.php of the component Backend. Executing manipulation of the argument uploadpath can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published and may be used.

CVSS3: 4.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-11136

A flaw has been found in YiFang CMS up to 2.0.2. The impacted element is the function webUploader of the file app/app/controller/File.php of the component Backend. Executing manipulation of the argument uploadpath can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published and may be used.

CVSS3: 4.7
0%
Низкий
4 месяца назад
github логотип
GHSA-32xq-c7f5-x98h

A flaw has been found in YiFang CMS up to 2.0.2. The impacted element is the function webUploader of the file app/app/controller/File.php of the component Backend. Executing manipulation of the argument uploadpath can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published and may be used.

CVSS3: 4.7
0%
Низкий
4 месяца назад

Уязвимостей на страницу