PT-2025-47010 · Codecanyon · News365

4M3Rr0R

·

Published

2025-11-14

·

Updated

2025-11-21

·

CVE-2025-13185

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bdtask/CodeCanyon News365 versions up to 7.0.3
Description A security flaw exists in Bdtask/CodeCanyon News365. The issue involves unrestricted file upload due to manipulation of the profile image/banner image argument within a function in the file '/admin/dashboard/profile'. This can be exploited remotely. The exploit has been publicly released. The vendor was contacted but did not respond.
Recommendations Versions prior to 7.0.3 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-13185

Affected Products

News365