PT-2025-16342 · Unknown · Perfreeblog

Cray0Nlee

·

Published

2025-04-15

·

Updated

2025-06-24

·

CVE-2025-29281

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PerfreeBlog version 4.0.11
Description The issue allows regular users to exploit an arbitrary file upload vulnerability in the attach component, enabling them to upload arbitrary files and execute code within them.
Recommendations For PerfreeBlog version 4.0.11, consider disabling the attach component until a patch is available to prevent exploitation of the arbitrary file upload vulnerability. Restrict access to the attach component to minimize the risk of uploading and executing malicious files.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-29281

Affected Products

Perfreeblog