CVE-2025-25361: Malicious File Upload
An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to execute arbitrary code via uploading a crafted svg or xml file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25361?
CVE-2025-25361 is considered a critical severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2025-25361?
To fix CVE-2025-25361, ensure to validate and sanitize all uploaded files and restrict file types to eliminate the risk of arbitrary code execution.
What versions of PublicCMS are affected by CVE-2025-25361?
CVE-2025-25361 affects PublicCMS v4.0.202406 and potentially earlier versions that use the vulnerable file upload component.
What impact does CVE-2025-25361 have on systems?
CVE-2025-25361 can allow attackers to upload malicious files, leading to arbitrary code execution and compromise of the server.
Is it safe to use PublicCMS with CVE-2025-25361 present?
It is unsafe to use PublicCMS with CVE-2025-25361 present without applying the necessary patches and mitigations.