No analysis available yet.
Vendor Solution
Update to AP 3.8.52.5 (Web 1.2.39.5) and install the hotfix, or update to AP 3.9.1 (Web 1.3.1) or later versions
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22060 | WinMatrix3 Web package developed by Simopro Technology has an Arbitrary File Upload vulnerability, allowing remote attackers with administrator privileges to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. |
Mon, 21 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Jul 2025 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 21 Jul 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WinMatrix3 Web package developed by Simopro Technology has an Arbitrary File Upload vulnerability, allowing remote attackers with administrator privileges to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Title | Simopro Technology|WinMatrix3 Web package - Arbitrary File Upload | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-07-21T15:39:46.038Z
Reserved: 2025-07-21T01:58:24.401Z
Link: CVE-2025-7917
Updated: 2025-07-21T15:39:41.340Z
Status : Deferred
Published: 2025-07-21T06:15:28.997
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-7917
No data.
OpenCVE Enrichment
No data.
-
CWE-434
Unrestricted Upload of File with Dangerous Type
EUVD