CVE-2025-25361

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-25361
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-25361.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-25361
Published
2025-03-06T19:15:27Z
Modified
2025-07-03T02:49:12.306752Z
Summary
[none]
Details

An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to execute arbitrary code via uploading a crafted svg or xml file.

References

Affected packages

Git / github.com/sanluan/publiccms

Affected ranges

Type
GIT
Repo
https://github.com/sanluan/publiccms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

Other

V2016

V4.*

V4.0.180707
V4.0.181024
V4.0.190312
V4.0.202004
V4.0.202011
V4.0.202107
V4.0.202107.b
V4.0.202107.c
V4.0.202107.d
V4.0.202107.f
V4.0.202204.a
V4.0.202204.b
V4.0.202204.c
V4.0.202204.d
V4.0.202302.a
V4.0.202302.b
V4.0.202302.c
V4.0.202302.d
V4.0.202302.e
V4.0.202302.f
V4.0.202406.a
V4.0.202406.b
V4.0.202406.c
V4.0.202406.d
V4.0.202406.e
V4.0.202406.f