CVE-2025-7895: Unrestricted Upload in harry0703 MoneyPrinterTurbo
A vulnerability, which was classified as critical, was found in harry0703 MoneyPrinterTurbo up to 1.2.6. Affected is the function upload_bgm_file of the file app/controllers/v1/video.py of the component File Extension Handler. The manipulation of the argument File leads to unrestricted upload. It is possible to launch the attack remotely.
CVE-2025-7895: Unrestricted Upload in harry0703 MoneyPrinterTurbo
Description
A vulnerability, which was classified as critical, was found in harry0703 MoneyPrinterTurbo up to 1.2.6. Affected is the function upload_bgm_file of the file app/controllers/v1/video.py of the component File Extension Handler. The manipulation of the argument File leads to unrestricted upload. It is possible to launch the attack remotely.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- VulDB
- Date Reserved
- 2025-07-19T11:19:51.559Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 687d012da83201eaac02df49
Added to database: 7/20/2025, 2:46:05 PM
Last updated: 7/20/2025, 2:46:05 PM
Views: 1
Related Threats
CVE-2025-46383: CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') in Emby Windows
MediumCVE-2025-46382: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in CyberArk IDP
MediumCVE-2025-7894: SQL Injection in Onyx
MediumCVE-2025-7893: Improper Export of Android Application Components in Foresight News App
MediumCVE-2025-7892: Improper Export of Android Application Components in IDnow App
MediumActions
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.