PT-2025-17374 · Wcms · Wcms

Icefoxh

·

Published

2025-04-19

·

Updated

2025-07-15

·

CVE-2025-3798

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WCMS version 11
Description A critical issue has been found in the Advertisement Image Handler component, affecting the sub function of the file app/admin/AdvadminController.php. This issue leads to unrestricted upload and can be initiated remotely. The exploit has been disclosed to the public and may be used.
Recommendations For WCMS version 11, consider disabling the sub function of the AdvadminController.php file until a patch is available. Restrict access to the Advertisement Image Handler component to minimize the risk of exploitation. Avoid using the vulnerable component until the issue is resolved.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-3798

Affected Products

Wcms