Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Yggcwhat

#22063of 53,624
10.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2025-23159
5.3
2025-05-29
Huocms · Huocms · CVE-2025-46078
**Name of the Vulnerable Software and Affected Versions** HuoCMS versions 3.5.1 and earlier **Description** The issue allows attackers to take control of the target server through file upload. **Recommendations** For HuoCMS versions 3.5.1 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2025-23160
5.3
2025-05-29
Huocms · Huocms · CVE-2025-46080
**Name of the Vulnerable Software and Affected Versions** HuoCMS version 3.5.1 **Description** The issue allows an attacker to exploit a flaw and bypass whitelist restrictions, enabling them to craft malicious files with specific suffixes and potentially gain control of the server. **Recommendations** For HuoCMS version 3.5.1, consider restricting file upload capabilities until a patch is available, and ensure that only authorized users have access to file upload functions to minimize the risk of exploitation.