Supermicro · Pcmt Supermicro-Cms · CVE-2021-25856
**Name of the Vulnerable Software and Affected Versions**
pcmt superMicro-CMS version 3.11
**Description**
An issue was discovered that allows attackers to delete files via a crafted image file in the `images.php` file.
**Recommendations**
For pcmt superMicro-CMS version 3.11, consider restricting access to the `images.php` file until a patch is available. As a temporary workaround, avoid using the `images.php` file to minimize the risk of exploitation.