Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Hao-Ni

#41890of 53,633
6.5Total CVSS
Vulnerabilities · 1
PT-2025-19928
6.5
2025-05-06
Unknown · Megagao Ssm-Erp · CVE-2025-4333
**Name of the Vulnerable Software and Affected Versions** feng ha ha/megagao ssm-erp and production ssm version 0.0.1 **Description** A critical issue affects the `uploadFile` function in the file src/main/java/com/megagao/production/ssm/service/impl/FileServiceImpl.java. The manipulation of the `uploadFile` argument allows for unrestricted file upload. This issue can be exploited remotely. **Recommendations** For version 0.0.1, consider disabling the `uploadFile` function until a patch is available to prevent unrestricted file uploads. Restrict access to the `FileServiceImpl.java` service to minimize the risk of exploitation. Avoid using the `uploadFile` argument in the affected service until the issue is resolved.