PT-2025-37409 · Fcba Zzm · Ics-Park Smart Park Management System

Yyjccc

·

Published

2025-09-14

·

Updated

2025-10-14

·

CVE-2025-10398

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions fcba zzm ics-park Smart Park Management System version 2.0
Description A security flaw has been discovered that allows for unrestricted file upload. The vulnerability affects unknown code within the FileUploadUtils.java file. The manipulation of the File argument enables the unrestricted upload of files, and the attack can be launched remotely. The exploit has been released publicly.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-10398

Affected Products

Ics-Park Smart Park Management System