PT-2025-32398 · Xoda · Xoda

Published

2025-08-08

·

Updated

2025-08-08

·

CVE-2012-10045

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions: XODA version 0.4.5
Description: XODA version 0.4.5 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary PHP code on the server. The flaw resides in the upload functionality, which fails to properly validate or restrict uploaded file types. An attacker can upload a .php file directly into the web-accessible files/ directory by crafting a multipart/form-data POST request and trigger its execution via a subsequent GET request.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2012-10045

Affected Products

Xoda