Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2025-13328 | A vulnerability has been found in newbee-mall 1.0 and classified as critical. Affected by this vulnerability is the function Upload of the file ltd/newbee/mall/controller/common/UploadController.java. The manipulation of the argument File leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 10 Oct 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Newbee-mall Project
Newbee-mall Project newbee-mall |
|
CPEs | cpe:2.3:a:newbee-mall_project:newbee-mall:1.0:*:*:*:*:*:*:* | |
Vendors & Products |
Newbee-mall Project
Newbee-mall Project newbee-mall |
Sat, 12 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Mon, 05 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 05 May 2025 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been found in newbee-mall 1.0 and classified as critical. Affected by this vulnerability is the function Upload of the file ltd/newbee/mall/controller/common/UploadController.java. The manipulation of the argument File leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. | |
Title | newbee-mall UploadController.java upload unrestricted upload | |
Weaknesses | CWE-284 CWE-434 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-05-05T13:54:10.160Z
Reserved: 2025-05-04T07:05:42.378Z
Link: CVE-2025-4259

Updated: 2025-05-05T13:54:03.111Z

Status : Analyzed
Published: 2025-05-05T03:15:23.477
Modified: 2025-10-10T19:09:34.887
Link: CVE-2025-4259

No data.

No data.