PT-2025-53626 · Unknown · Jackq Xcms
Formanagain
·
Published
2025-12-27
·
Updated
2025-12-27
·
CVE-2025-15110
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
jackq XCMS versions prior to 3fab5342cc509945a7ce1b8ec39d19f701b89261
Description
A flaw exists in jackq XCMS that allows for unrestricted file upload. The issue is located in the
Upload function within the Admin/Home/Controller/ProductImageController.class.php file of the Backend component. Manipulation of the File argument enables remote attackers to upload files without restrictions. The exploit for this issue has been publicly disclosed and is potentially being used in active attacks. Reports indicate offensive activities targeting this vulnerability.Recommendations
Versions prior to 3fab5342cc509945a7ce1b8ec39d19f701b89261 should be updated. As a temporary workaround, consider restricting access to the
ProductImageController.class.php file or disabling the Upload function until a suitable update is available.Exploit
Fix
Improper Access Control
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jackq Xcms