PT-2025-15701 · Verydows · Verydows
Jaylan545
·
Published
2025-04-09
·
Updated
2025-04-10
·
CVE-2025-29394
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
verydows version 2.0
Description:
The issue is related to insecure permissions, allowing a remote attacker to execute arbitrary code by uploading a specific file type. This can be achieved through the action of loading a particular type of file, which is not further specified.
Recommendations:
For verydows version 2.0, consider restricting access to file uploads until a fix is available, or apply specific configuration changes to mitigate the risk of arbitrary code execution.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Verydows