PT-2025-5197 · Unknown · Smallerik File Browser

Colin Xu

·

Published

2025-01-22

·

Updated

2025-01-22

·

CVE-2025-23918

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Smallerik File Browser versions n/a through 1.1
Description The issue allows for the unrestricted upload of files with dangerous types, enabling attackers to upload a web shell to a web server. This can be exploited by uploading malicious files, such as web shells, onto a server.
Recommendations Update to version 1.1 to resolve the issue. As a temporary workaround, consider restricting file uploads to prevent malicious files from being uploaded onto the server.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-23918

Affected Products

Smallerik File Browser