File upload vulnerability in WebErpMesv2 1.17 in the app/Http/Controllers/FactoryController.php controller. This flaw allows an authenticated attacker to upload arbitrary files, including PHP scripts, which can be accessed via direct GET requests, potentially resulting in remote code execution (RCE) on the web server.
References
Configurations
No configuration.
History
26 Aug 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-616 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
Summary |
|
25 Aug 2025, 20:24
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-25 20:15
Updated : 2025-08-26 16:15
NVD link : CVE-2025-52130
Mitre link : CVE-2025-52130
CVE.ORG link : CVE-2025-52130
JSON object : View
Products Affected
No product.
CWE
CWE-616
Incomplete Identification of Uploaded File Variables (PHP)