CVE-2025-15423: EmpireSoft EmpireCMS connect.php CheckSaveTranFiletype unrestricted upload
A vulnerability has been found in EmpireSoft EmpireCMS up to 8.0. Impacted is the function CheckSaveTranFiletype of the file e/class/connect.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15423?
CVE-2025-15423 is classified as a high severity vulnerability due to the potential for unrestricted file uploads.
How do I fix CVE-2025-15423?
To mitigate CVE-2025-15423, update EmpireSoft EmpireCMS to the latest version beyond 8.0 that addresses this vulnerability.
What type of vulnerability is CVE-2025-15423?
CVE-2025-15423 is an unrestricted file upload vulnerability found in EmpireSoft EmpireCMS.
Who is affected by CVE-2025-15423?
CVE-2025-15423 affects all versions of EmpireSoft EmpireCMS up to and including 8.0.
Can CVE-2025-15423 be exploited remotely?
Yes, CVE-2025-15423 can be exploited remotely, allowing attackers to upload malicious files.