PT-2025-52621 · Liweiyi · Chestnutcms

Yuccun

·

Published

2025-12-22

·

Updated

2025-12-31

·

CVE-2025-15009

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions liweiyi ChestnutCMS versions up to 1.5.8
Description A flaw exists in liweiyi ChestnutCMS up to version 1.5.8. This issue affects the FilenameUtils.getExtension function within the Filename Handler component, located in the file /dev-api/common/upload. Manipulation of the File argument can lead to unrestricted file upload, and the attack can be launched remotely. An exploit for this issue has been published.
Recommendations Versions prior to 1.5.8 are vulnerable. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-15009

Affected Products

Chestnutcms