HuoCMS V3.5.1 has a File Upload Vulnerability. An attacker can exploit this flaw to bypass whitelist restrictions and craft malicious files with specific suffixes, thereby gaining control of the server.
History

Wed, 04 Jun 2025 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Huocms
Huocms huocms
CPEs cpe:2.3:a:huocms:huocms:3.5.1:*:*:*:*:*:*:*
Vendors & Products Huocms
Huocms huocms

Thu, 29 May 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-434
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 29 May 2025 14:00:00 +0000

Type Values Removed Values Added
Description HuoCMS V3.5.1 has a File Upload Vulnerability. An attacker can exploit this flaw to bypass whitelist restrictions and craft malicious files with specific suffixes, thereby gaining control of the server.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-05-29T00:00:00.000Z

Updated: 2025-05-29T14:09:30.325Z

Reserved: 2025-04-22T00:00:00.000Z

Link: CVE-2025-46080

cve-icon Vulnrichment

Updated: 2025-05-29T14:07:45.489Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-29T14:15:37.220

Modified: 2025-06-04T19:59:02.890

Link: CVE-2025-46080

cve-icon Redhat

No data.