CVE-2025-7100: Unrestricted Upload in BoyunCMS
A vulnerability was found in BoyunCMS up to 1.4.20 and classified as critical. Affected by this issue is some unknown functionality of the file /application/user/controller/Index.php. The manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-7100: Unrestricted Upload in BoyunCMS
Description
A vulnerability was found in BoyunCMS up to 1.4.20 and classified as critical. Affected by this issue is some unknown functionality of the file /application/user/controller/Index.php. The manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- VulDB
- Date Reserved
- 2025-07-05T17:35:20.010Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 686b17386f40f0eb72d9d217
Added to database: 7/7/2025, 12:39:20 AM
Last updated: 7/7/2025, 12:39:20 AM
Views: 1
Related Threats
CVE-2025-7101: Code Injection in BoyunCMS
MediumCVE-2025-7099: Deserialization in BoyunCMS
MediumCVE-2025-7098: Path Traversal in Comodo Internet Security Premium
MediumCVE-2025-3108: CWE-1112 Incomplete Documentation of Program Execution in run-llama run-llama/llama_index
MediumCVE-2025-7097: OS Command Injection in Comodo Internet Security Premium
CriticalActions
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.