Metrics
Affected Vendors & Products
Mon, 25 Aug 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 25 Aug 2025 09:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wanglongcn
Wanglongcn yifang |
|
Vendors & Products |
Wanglongcn
Wanglongcn yifang |
Mon, 25 Aug 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw has been found in YiFang CMS up to 2.0.5. This affects the function mergeMultipartUpload of the file app/utils/base/plugin/P_file.php. This manipulation of the argument File causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | YiFang CMS P_file.php mergeMultipartUpload unrestricted upload | |
Weaknesses | CWE-284 CWE-434 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-08-25T00:32:06.112Z
Updated: 2025-08-25T20:29:09.150Z
Reserved: 2025-08-24T14:47:38.982Z
Link: CVE-2025-9400

Updated: 2025-08-25T20:29:02.085Z

Status : Awaiting Analysis
Published: 2025-08-25T01:15:36.703
Modified: 2025-08-25T20:24:45.327
Link: CVE-2025-9400

No data.