WinMatrix3 Web package developed by Simopro Technology has an Arbitrary File Upload vulnerability, allowing remote attackers with administrator privileges to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Metrics
Affected Vendors & Products
References
History
Mon, 21 Jul 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 21 Jul 2025 07:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Mon, 21 Jul 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | WinMatrix3 Web package developed by Simopro Technology has an Arbitrary File Upload vulnerability, allowing remote attackers with administrator privileges to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
Title | Simopro Technology|WinMatrix3 Web package - Arbitrary File Upload | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: twcert
Published: 2025-07-21T06:08:38.612Z
Updated: 2025-07-21T15:39:46.038Z
Reserved: 2025-07-21T01:58:24.401Z
Link: CVE-2025-7917

Updated: 2025-07-21T15:39:41.340Z

Status : Awaiting Analysis
Published: 2025-07-21T06:15:28.997
Modified: 2025-07-22T13:06:07.260
Link: CVE-2025-7917

No data.