CVE 5.1 MEDIUM

YiFang CMS Backend File.php webUploader unrestricted upload_CVE-2025-11136

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A flaw has been found in YiFang CMS up to 2.0.2. The impacted element is the function webUploader of the file app/app/controller/File.php of the component Backend. Executing manipulation of the argument uploadpath can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published and may be used.

Basic Information

ID CVE-2025-11136
Source VulDB
Published Sep 29, 2025 at 02:02

Affected Product

Vendor YiFang
Product CMS
Version 2.0.0
Affected Versions YiFang CMS 2.0.0
YiFang CMS 2.0.1
YiFang CMS 2.0.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.