PT-2025-34810 · Unknown · Badaso Cms
Pat.Sanitjairak
·
Published
2025-08-26
·
Updated
2025-08-26
·
CVE-2025-52353
Pat.Sanitjairak
·
Published
2025-08-26
·
Updated
2025-08-26
·
CVE-2025-52353
9.8
Critical
Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Badaso CMS version 2.9.11
Description:
The Media Manager allows authenticated users to upload files containing embedded PHP code via the file-upload endpoint, bypassing content-type validation. When such a file is accessed via its URL, the server executes the PHP payload, enabling an attacker to run arbitrary system commands and achieve full compromise of the underlying host. This was demonstrated by embedding a backdoor within a PDF and renaming it with a .php extension.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Code Injection
Unrestricted File Upload