PT-2025-9178 · Unknown · Zorlan Skycaiji

Sheratan

+1

·

Published

2025-03-01

·

Updated

2025-06-12

·

CVE-2025-1791

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zorlan SkyCaiji version 2.9
Description A critical vulnerability has been found in Zorlan SkyCaiji, affecting the fileAction function of the vendor/skycaiji/app/admin/controller/Tool.php file. The manipulation of the save data argument leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Recommendations As a temporary workaround, consider disabling the fileAction function until a patch is available. Restrict access to the vendor/skycaiji/app/admin/controller/Tool.php file to minimize the risk of exploitation. Avoid using the save data argument in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-1791

Affected Products

Zorlan Skycaiji