Skip to main content

CVE-2025-8526: Unrestricted Upload in Exrick xboot

Medium
VulnerabilityCVE-2025-8526cvecve-2025-8526
Published: Mon Aug 04 2025 (08/04/2025, 21:02:05 UTC)
Source: CVE Database V5
Vendor/Project: Exrick
Product: xboot

Description

A vulnerability was found in Exrick xboot up to 3.3.4. It has been declared as critical. This vulnerability affects the function Upload of the file xboot-fast/src/main/java/cn/exrick/xboot/modules/base/controller/common/UploadController.java. The manipulation of the argument File leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

Technical Details

Data Version
5.1
Assigner Short Name
VulDB
Date Reserved
2025-08-04T06:51:22.039Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6891237cad5a09ad00e331bd

Added to database: 8/4/2025, 9:17:48 PM

Last updated: 8/4/2025, 9:17:48 PM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats