Metrics
Affected Vendors & Products
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 29 Sep 2025 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw has been found in YiFang CMS up to 2.0.2. The impacted element is the function webUploader of the file app/app/controller/File.php of the component Backend. Executing manipulation of the argument uploadpath can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published and may be used. | |
Title | YiFang CMS Backend File.php webUploader unrestricted upload | |
Weaknesses | CWE-284 CWE-434 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-09-29T02:02:05.045Z
Reserved: 2025-09-28T15:47:43.792Z
Link: CVE-2025-11136

No data.

Status : Received
Published: 2025-09-29T03:15:42.063
Modified: 2025-09-29T03:15:42.063
Link: CVE-2025-11136

No data.

No data.