PT-2025-31467 · Unknown · Openviglet Shio
1098024193
·
Published
2025-07-31
·
Updated
2025-07-31
·
CVE-2025-8344
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
openviglet shio versions up to 0.3.8
Description
A critical vulnerability has been identified in openviglet shio up to version 0.3.8. The
shStaticFileUpload function within the file shio-app/src/main/java/com/viglet/shio/api/staticfile/ShStaticFileAPI.java is affected. Manipulation of the filename argument leads to unrestricted file upload, and the attack can be launched remotely. The exploit for this issue has been publicly disclosed.Recommendations
For versions up to 0.3.8, restrict or disable the
shStaticFileUpload function to prevent unrestricted file uploads.Exploit
Fix
Improper Access Control
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openviglet Shio