PT-2025-36538 · Unknown · Siemprecms

Drewbyte

·

Published

2025-09-09

·

Updated

2025-09-14

·

CVE-2025-10116

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: SiempreCMS versions prior to 1.3.7
Description: A vulnerability was identified in SiempreCMS that allows for unrestricted file upload through manipulation of unknown code within the /docs/admin/file upload.php file. The attack can be launched remotely. The exploit is publicly available.
Recommendations: Update to a version prior to 1.3.7. As a temporary workaround, restrict access to the /docs/admin/file upload.php file.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-10116

Affected Products

Siemprecms