PT-2025-19328 · Unknown · Newbee-Mall

1098024193

·

Published

2025-05-05

·

Updated

2025-05-05

·

CVE-2025-4259

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions newbee-mall version 1.0
Description A critical vulnerability has been found in the function Upload of the file ltd/newbee/mall/controller/common/UploadController.java. The manipulation of the argument File leads to unrestricted upload. The attack can be launched remotely.
Recommendations As a temporary workaround, consider disabling the Upload function in the UploadController.java file until a patch is available. Restrict access to the UploadController.java file to minimize the risk of exploitation. Avoid using the File argument in the Upload function until the issue is resolved.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-4259

Affected Products

Newbee-Mall