PT-2025-53626 · Unknown · Jackq Xcms

Formanagain

·

Published

2025-12-27

·

Updated

2025-12-27

·

CVE-2025-15110

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions jackq XCMS versions prior to 3fab5342cc509945a7ce1b8ec39d19f701b89261
Description A flaw exists in jackq XCMS that allows for unrestricted file upload. The issue is located in the Upload function within the Admin/Home/Controller/ProductImageController.class.php file of the Backend component. Manipulation of the File argument enables remote attackers to upload files without restrictions. The exploit for this issue has been publicly disclosed and is potentially being used in active attacks. Reports indicate offensive activities targeting this vulnerability.
Recommendations Versions prior to 3fab5342cc509945a7ce1b8ec39d19f701b89261 should be updated. As a temporary workaround, consider restricting access to the ProductImageController.class.php file or disabling the Upload function until a suitable update is available.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-15110

Affected Products

Jackq Xcms