PT-2025-16261 · Westboy · Cicadascms
Keke
·
Published
2025-04-14
·
Updated
2025-04-14
·
CVE-2025-3585
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Westboy CicadasCMS version 1.0
Description:
A critical vulnerability has been found in Westboy CicadasCMS, affecting an unknown part of the file /upload/ of the component JSP Parser. The manipulation of the argument
File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.Recommendations:
As a temporary workaround, consider disabling the file upload functionality in the /upload/ component until a patch is available.
Restrict access to the JSP Parser component to minimize the risk of exploitation.
Avoid using the
File argument in the affected component until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Improper Access Control
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cicadascms