PT-2025-38637 · Selleo · Selleo Mentingo
Khanmarshal
·
Published
2025-09-20
·
Updated
2025-09-20
·
CVE-2025-10741
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Selleo Mentingo versions prior to 2025.08.28
Description
A security issue has been identified in Selleo Mentingo. The vulnerability resides in an unknown function within the Profile Picture Handler component. Manipulation of the
userAvatar argument allows for unrestricted file upload, and the attack can be performed remotely. The exploit has been publicly disclosed, and the vendor was notified but did not respond.Recommendations
Versions prior to 2025.08.28: Restrict or disable the use of the Profile Picture Handler component until a resolution is available. Avoid uploading files through the
userAvatar argument.Exploit
Fix
Improper Access Control
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Selleo Mentingo