PT-2025-19803 · Ideacms · Ideacms

Enenen

·

Published

2025-05-05

·

Updated

2025-05-06

·

CVE-2025-4291

CVSS v2.0
6.5
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P

Name of the Vulnerable Software and Affected Versions:

IdeaCMS versions up to 1.6

Description:

A critical vulnerability was found in IdeaCMS, affecting the `saveUpload` function. This vulnerability allows for unrestricted upload and can be exploited remotely. The exploit has been disclosed to the public and may be used.

Recommendations:

For IdeaCMS versions up to 1.6, consider disabling the `saveUpload` function as a temporary workaround until a patch is available. Restrict access to the affected function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-4291

Affected Products

Ideacms