PT-2025-23615 · Erupt · Erupt
Cafe-Tea
·
Publicado
2025-06-03
·
Atualizado
2025-06-23
·
CVE-2025-45855
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
erupt version 1.12.19
Description
The issue is related to an arbitrary file upload vulnerability in the /upload/GoodsCategory/image component, which allows attackers to execute arbitrary code by uploading a crafted file.
Recommendations
For erupt version 1.12.19, consider disabling the /upload/GoodsCategory/image component until a patch is available to prevent arbitrary file uploads and subsequent code execution. Restrict access to this component to minimize the risk of exploitation. Avoid using this component for file uploads until the issue is resolved.
Correção
LPE
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Erupt