CVE-2025-15415: xnx3 wangmarket XML File uploadImage.do uploadImage unrestricted upload
A vulnerability has been found in xnx3 wangmarket up to 6.4. The impacted element is the function uploadImage of the file /sits/uploadImage.do of the component XML File Handler. The manipulation of the argument image leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15415?
CVE-2025-15415 is considered a high severity vulnerability due to unrestricted file upload risk.
How do I fix CVE-2025-15415?
To fix CVE-2025-15415, update xnx3 wangmarket to version 6.5 or later to mitigate the vulnerability.
What components are affected by CVE-2025-15415?
CVE-2025-15415 affects the uploadImage function in the XML File Handler of xnx3 wangmarket up to version 6.4.
Can CVE-2025-15415 be exploited remotely?
Yes, CVE-2025-15415 can be exploited remotely due to the nature of the unrestricted file upload vulnerability.
What is the impact of exploiting CVE-2025-15415?
Exploiting CVE-2025-15415 can allow attackers to upload malicious files, potentially leading to remote code execution.