PT-2025-47010 · Codecanyon · News365
4M3Rr0R
·
Published
2025-11-14
·
Updated
2025-11-21
·
CVE-2025-13185
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Bdtask/CodeCanyon News365 versions up to 7.0.3
Description
A security flaw exists in Bdtask/CodeCanyon News365. The issue involves unrestricted file upload due to manipulation of the
profile image/banner image argument within a function in the file '/admin/dashboard/profile'. This can be exploited remotely. The exploit has been publicly released. The vendor was contacted but did not respond.Recommendations
Versions prior to 7.0.3 are affected.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Access Control
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
News365