PT-2025-22769 · Unknown · Ajar In5 Embed

Lvt-Tholv2K

·

Published

2025-05-23

·

Updated

2025-05-24

·

CVE-2025-47642

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ajar in5 Embed versions 3.1.5 and earlier
Description The issue allows for the unrestricted upload of files with dangerous types, enabling an attacker to upload a web shell to a web server. This can lead to further exploitation and potential control of the server.
Recommendations For Ajar in5 Embed versions 3.1.5 and earlier, consider restricting file uploads to only allow safe file types until a patch is available. As a temporary workaround, restrict access to the file upload feature to minimize the risk of exploitation. Avoid using the file upload feature in Ajar in5 Embed until the issue is resolved.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-47642

Affected Products

Ajar In5 Embed