PT-2025-17412 · Unknown · Kuangsimplebbs
Caigo
·
Published
2025-04-20
·
Updated
2025-04-20
·
CVE-2025-3830
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
KuangSimpleBBS version 1.0
Description
A critical vulnerability has been found in KuangSimpleBBS, affecting the
fileUpload function in the QuestionController.java file. The manipulation of the editormd-image-file argument leads to unrestricted file upload. This issue can be exploited remotely. The exploit has been publicly disclosed and may be used.Recommendations
For KuangSimpleBBS version 1.0, as a temporary workaround, consider disabling the
fileUpload function until a patch is available. Restrict access to the QuestionController.java file to minimize the risk of exploitation. Avoid using the editormd-image-file argument in the affected function until the issue is resolved.Exploit
Fix
Improper Access Control
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kuangsimplebbs