A vulnerability has been found in shishuocms 1.1 and classified as critical. This vulnerability affects the function handleRequest of the file src/main/java/com/shishuo/cms/action/manage/ManageUpLoadAction.java. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
History

Wed, 05 Mar 2025 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Shishuocms Project
Shishuocms Project shishuocms
CPEs cpe:2.3:a:shishuocms_project:shishuocms:1.1:*:*:*:*:*:*:*
Vendors & Products Shishuocms Project
Shishuocms Project shishuocms

Tue, 04 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 23:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in shishuocms 1.1 and classified as critical. This vulnerability affects the function handleRequest of the file src/main/java/com/shishuo/cms/action/manage/ManageUpLoadAction.java. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Title shishuocms ManageUpLoadAction.java handleRequest unrestricted upload
Weaknesses CWE-284
CWE-434
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-03-03T23:31:04.985Z

Updated: 2025-03-04T15:18:54.596Z

Reserved: 2025-03-03T18:07:17.630Z

Link: CVE-2025-1890

cve-icon Vulnrichment

Updated: 2025-03-04T15:15:57.406Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-04T00:15:31.190

Modified: 2025-03-05T14:05:15.387

Link: CVE-2025-1890

cve-icon Redhat

No data.