PT-2025-16217 · Veal98 · Veal98
Caigo
·
Published
2025-04-14
·
Updated
2025-04-19
·
CVE-2025-3566
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
veal98 小牛肉 Echo 开源社区系统 version 4.2
Description:
A critical issue has been found in the function
uploadMdPic of the file /discuss/uploadMdPic. The manipulation of the argument editormd-image-file leads to unrestricted upload. The attack may be initiated remotely.Recommendations:
For version 4.2, as a temporary workaround, consider disabling the
uploadMdPic function until a patch is available. Restrict access to the /discuss/uploadMdPic endpoint to minimize the risk of exploitation. Avoid using the editormd-image-file argument in the affected endpoint until the issue is resolved.Exploit
Fix
Unrestricted File Upload
XSS
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Veal98