First published: Wed Mar 12 2025(Updated: )
A vulnerability, which was classified as critical, has been found in zzskzy Warehouse Refinement Management System 1.3. Affected by this issue is the function UploadCrash of the file /crash/log/SaveCrash.ashx. The manipulation of the argument file leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
zzskzy Warehouse Refinement Management System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-2216 is classified as critical due to the potential for unrestricted file uploads.
To fix CVE-2025-2216, implement input validation and restrict file upload functionality in the UploadCrash function.
CVE-2025-2216 affects zzskzy Warehouse Refinement Management System version 1.3.
CVE-2025-2216 is an unrestricted file upload vulnerability.
Exploiting CVE-2025-2216 could allow attackers to upload malicious files, potentially leading to remote code execution.