No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25746 | File upload vulnerability in WebErpMesv2 1.17 in the app/Http/Controllers/FactoryController.php controller. This flaw allows an authenticated attacker to upload arbitrary files, including PHP scripts, which can be accessed via direct GET requests, potentially resulting in remote code execution (RCE) on the web server. |
Tue, 26 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-616 | |
| Metrics |
cvssV3_1
|
Mon, 25 Aug 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | File upload vulnerability in WebErpMesv2 1.17 in the app/Http/Controllers/FactoryController.php controller. This flaw allows an authenticated attacker to upload arbitrary files, including PHP scripts, which can be accessed via direct GET requests, potentially resulting in remote code execution (RCE) on the web server. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-08-26T15:29:58.501Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-52130
Updated: 2025-08-26T15:29:49.864Z
Status : Deferred
Published: 2025-08-25T20:15:40.700
Modified: 2026-06-17T09:36:00.867
Link: CVE-2025-52130
No data.
OpenCVE Enrichment
No data.
-
CWE-616
Incomplete Identification of Uploaded File Variables (PHP)
EUVD