PT-2025-17412 · Unknown · Kuangsimplebbs

·

CVE-2025-3830

·

Published

2025-04-20

·

Updated

2025-04-20

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions KuangSimpleBBS version 1.0
Description A critical vulnerability has been found in KuangSimpleBBS, affecting the fileUpload function in the QuestionController.java file. The manipulation of the editormd-image-file argument leads to unrestricted file upload. This issue can be exploited remotely. The exploit has been publicly disclosed and may be used.
Recommendations For KuangSimpleBBS version 1.0, as a temporary workaround, consider disabling the fileUpload function until a patch is available. Restrict access to the QuestionController.java file to minimize the risk of exploitation. Avoid using the editormd-image-file argument in the affected function until the issue is resolved.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-3830

Affected Products

Kuangsimplebbs