Логотип exploitDog
bind:CVE-2025-52353
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-52353

Количество 2

Количество 2

nvd логотип

CVE-2025-52353

6 месяцев назад

An arbitrary code execution vulnerability in Badaso CMS 2.9.11. The Media Manager allows authenticated users to upload files containing embedded PHP code via the file-upload endpoint, bypassing content-type validation. When such a file is accessed via its URL, the server executes the PHP payload, enabling an attacker to run arbitrary system commands and achieve full compromise of the underlying host. This has been demonstrated by embedding a backdoor within a PDF and renaming it with a .php extension.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-gqp9-jh35-439m

6 месяцев назад

Badaso CMS file upload vulnerability

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-52353

An arbitrary code execution vulnerability in Badaso CMS 2.9.11. The Media Manager allows authenticated users to upload files containing embedded PHP code via the file-upload endpoint, bypassing content-type validation. When such a file is accessed via its URL, the server executes the PHP payload, enabling an attacker to run arbitrary system commands and achieve full compromise of the underlying host. This has been demonstrated by embedding a backdoor within a PDF and renaming it with a .php extension.

CVSS3: 9.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-gqp9-jh35-439m

Badaso CMS file upload vulnerability

0%
Низкий
6 месяцев назад

Уязвимостей на страницу