5.1
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A flaw has been found in YiFang CMS up to 2.0.2. The impacted element is the function webUploader of the file app/app/controller/File.php of the component Backend. Executing manipulation of the argument uploadpath can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published and may be used.
Basic Information
ID
CVE-2025-11136
Source
VulDB
Published
Sep 29, 2025 at 02:02
Affected Product
Vendor
YiFang
Product
CMS
Version
2.0.0
Affected Versions
YiFang CMS 2.0.0
YiFang CMS 2.0.1
YiFang CMS 2.0.2
YiFang CMS 2.0.1
YiFang CMS 2.0.2