PT-2025-48813 · Unknown · Proudmubai Gofilm
A123456
·
Published
2025-12-03
·
Updated
2025-12-03
·
CVE-2025-13949
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ProudMuBai GoFilm versions 1.0.0 through 1.0.1
Description
A flaw exists in ProudMuBai GoFilm that allows for unrestricted file uploads. This issue is located within the
SingleUpload function of the /server/controller/FileController.go file. The File argument can be manipulated to achieve this. The attack can be initiated remotely, and a publicly available exploit exists. The vendor was notified but did not respond.Recommendations
Update ProudMuBai GoFilm to a version newer than 1.0.1.
As a temporary workaround, restrict access to the
SingleUpload function in /server/controller/FileController.go until a patch is available.Exploit
Fix
Improper Access Control
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Proudmubai Gofilm