CVE-2025-45242: High severity Rhymix Rhymix vulnerability
Published May 5, 2025
·Updated
Rhymix v2.1.22 was discovered to contain an arbitrary file deletion vulnerability via the procFileAdminEditImage method in /file/file.admin.controller.php.
Affected Software
2 affected components
Rhymix Rhymix
Rhymix Rhymix=2.1.22
Event History
May 5, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-45242?
CVE-2025-45242 has been classified as critical due to its ability to allow arbitrary file deletion.
2
How do I fix CVE-2025-45242?
To address CVE-2025-45242, upgrade to the latest version of Rhymix that has patched this vulnerability.
3
What is the impact of CVE-2025-45242?
The impact of CVE-2025-45242 is that it allows attackers to delete files from the server, potentially leading to data loss or application downtime.
4
Which versions of Rhymix are affected by CVE-2025-45242?
CVE-2025-45242 affects Rhymix version 2.1.22 and possibly earlier versions.
5
How can I prevent exploitation of CVE-2025-45242 until I can apply a fix?
To prevent exploitation of CVE-2025-45242, restrict access to the administrative functions and closely monitor server logs for suspicious activities.