5.1
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A weakness has been identified in Willow CMS up to 1.4.0. Impacted is an unknown function of the file /admin/images/add. This manipulation causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.
Basic Information
ID
CVE-2025-12331
Source
VulDB
Published
Oct 27, 2025 at 22:02
Affected Product
Vendor
Willow
Product
CMS
Version
1.0
Affected Versions
Willow CMS 1.0
Willow CMS 1.1
Willow CMS 1.2
Willow CMS 1.3
Willow CMS 1.4.0
Willow CMS 1.1
Willow CMS 1.2
Willow CMS 1.3
Willow CMS 1.4.0