PT-2025-19328 · Unknown · Newbee-Mall
1098024193
·
Published
2025-05-05
·
Updated
2025-05-05
·
CVE-2025-4259
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
newbee-mall version 1.0
Description
A critical vulnerability has been found in the function Upload of the file ltd/newbee/mall/controller/common/UploadController.java. The manipulation of the argument
File leads to unrestricted upload. The attack can be launched remotely.Recommendations
As a temporary workaround, consider disabling the Upload function in the UploadController.java file until a patch is available.
Restrict access to the UploadController.java file to minimize the risk of exploitation.
Avoid using the
File argument in the Upload function until the issue is resolved.Exploit
Fix
Improper Access Control
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Newbee-Mall