PT-2025-31467 · Unknown · Openviglet Shio

1098024193

·

Published

2025-07-31

·

Updated

2025-07-31

·

CVE-2025-8344

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openviglet shio versions up to 0.3.8
Description A critical vulnerability has been identified in openviglet shio up to version 0.3.8. The shStaticFileUpload function within the file shio-app/src/main/java/com/viglet/shio/api/staticfile/ShStaticFileAPI.java is affected. Manipulation of the filename argument leads to unrestricted file upload, and the attack can be launched remotely. The exploit for this issue has been publicly disclosed.
Recommendations For versions up to 0.3.8, restrict or disable the shStaticFileUpload function to prevent unrestricted file uploads.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-8344

Affected Products

Openviglet Shio