CVE-2025-3842: panhainan DS-Java FileUpload.java uploadUserPic.action code injection
A vulnerability was found in panhainan DS-Java 1.0 and classified as critical. This issue affects the function uploadUserPic.action of the file src/com/phn/action/FileUpload.java. The manipulation of the argument fileUpload leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3842?
CVE-2025-3842 is classified as critical due to its potential for remote code injection.
How do I fix CVE-2025-3842?
To fix CVE-2025-3842, ensure that the file upload feature in panhainan DS-Java 1.0 is properly validated and sanitized.
Which versions of software are affected by CVE-2025-3842?
CVE-2025-3842 affects panhainan DS-Java 1.0, specifically the uploadUserPic.action function.
What type of vulnerability is CVE-2025-3842?
CVE-2025-3842 is a code injection vulnerability that can be exploited through the fileUpload parameter.
Can CVE-2025-3842 be exploited remotely?
Yes, CVE-2025-3842 can be exploited remotely, allowing attackers to execute arbitrary code on the server.