PT-2025-47398 · Unknown · Mozart Fm Transmitter
Published
2025-11-18
·
Updated
2025-11-19
·
CVE-2025-63227
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Mozart FM Transmitter version WEBMOZZI-00287
Description
The Mozart FM Transmitter web management interface version WEBMOZZI-00287 has an unrestricted file upload issue in the
/patch.php endpoint. An attacker with administrative access can upload arbitrary files, such as PHP webshells, to the /patch/ directory. Successful exploitation allows the attacker to execute arbitrary commands on the server, potentially resulting in full system compromise.Recommendations
Apply restrictions to file uploads in the
/patch.php endpoint.
Restrict administrative access to the web management interface.Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mozart Fm Transmitter