Metrics
Affected Vendors & Products
Mon, 24 Mar 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sun, 23 Mar 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in Yue Lao Blind Box 月老盲盒 up to 4.0. It has been declared as critical. This vulnerability affects the function base64image of the file /app/controller/Upload.php. The manipulation of the argument data leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
Title | Yue Lao Blind Box 月老盲盒 Upload.php base64image unrestricted upload | |
Weaknesses | CWE-284 CWE-434 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-03-23T22:00:09.708Z
Updated: 2025-03-24T15:59:22.537Z
Reserved: 2025-03-22T13:44:02.496Z
Link: CVE-2025-2671

Updated: 2025-03-24T15:59:12.186Z

Status : Received
Published: 2025-03-23T22:15:13.513
Modified: 2025-03-23T22:15:13.513
Link: CVE-2025-2671

No data.