Arbitrary File Upload in SMG Software’s Information Portal

CVE Details

Basic Information

Title Arbitrary File Upload in SMG Software’s Information Portal
Type cve
Published 2025-07-24T12:45:22.450Z
Modified 2025-07-24T13:36:01.931Z

Product Information

Vendor SMG Software
Product Information Portal
Version 0

CVSS Information

Base Score 10.0 (CRITICAL)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

AI Analysis

AI Description This vulnerability allows attackers to upload malicious files and execute arbitrary OS commands, potentially leading to code injection and web shell deployment. It affects versions of the Information Portal before 13.06.2025.
AI Severity Critical
AI Vendor SMG Software
AI Product Information Portal
AI Version Before 13.06.2025

Affected Products

  • SMG Software Information Portal 0

Additional Information

CWE List CWE-434, CWE-78
Source TR-CERT

Description

Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) vulnerability in SMG Software Information Portal allows Code Injection, Upload a Web Shell to a Web Server, Code Inclusion. This issue affects Information Portal: before 13.06.2025.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.