PT-2025-38637 · Selleo · Selleo Mentingo

Khanmarshal

·

Published

2025-09-20

·

Updated

2025-09-20

·

CVE-2025-10741

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Selleo Mentingo versions prior to 2025.08.28
Description A security issue has been identified in Selleo Mentingo. The vulnerability resides in an unknown function within the Profile Picture Handler component. Manipulation of the userAvatar argument allows for unrestricted file upload, and the attack can be performed remotely. The exploit has been publicly disclosed, and the vendor was notified but did not respond.
Recommendations Versions prior to 2025.08.28: Restrict or disable the use of the Profile Picture Handler component until a resolution is available. Avoid uploading files through the userAvatar argument.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-10741

Affected Products

Selleo Mentingo