An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Upload function.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.yuque.com/morysummer/vx41bz/cyql4n0xiubspntl | Exploit Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    22 Apr 2025, 16:27
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:personal-management-system:personal_management_system:1.4.65:*:*:*:*:*:*:* | |
| References | () https://www.yuque.com/morysummer/vx41bz/cyql4n0xiubspntl - Exploit, Third Party Advisory | |
| First Time | 
        
        Personal-management-system
         Personal-management-system personal Management System  | 
21 Apr 2025, 18:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 6.5  | 
| CWE | CWE-918 | 
21 Apr 2025, 14:23
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
        
        
  | 
17 Apr 2025, 21:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-04-17 21:15
Updated : 2025-04-22 16:27
NVD link : CVE-2025-29454
Mitre link : CVE-2025-29454
CVE.ORG link : CVE-2025-29454
JSON object : View
Products Affected
                personal-management-system
- personal_management_system
 
CWE
                
                    
                        
                        CWE-918
                        
            Server-Side Request Forgery (SSRF)
