Verydows · Verydows · CVE-2025-29394
Name of the Vulnerable Software and Affected Versions:
verydows version 2.0
Description:
The issue is related to insecure permissions, allowing a remote attacker to execute arbitrary code by uploading a specific file type. This can be achieved through the action of loading a particular type of file, which is not further specified.
Recommendations:
For verydows version 2.0, consider restricting access to file uploads until a fix is available, or apply specific configuration changes to mitigate the risk of arbitrary code execution.