A weakness has been identified in xuhuisheng lemon up to 1.13.0. This affects the function uploadImage of the file CmsArticleController.java of the component com.mossle.cms.web.CmsArticleController.uploadImage. This manipulation of the argument Upload causes unrestricted upload. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.
Metrics
Affected Vendors & Products
References
History
Mon, 25 Aug 2025 09:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Xuhuisheng
Xuhuisheng lemon |
|
Vendors & Products |
Xuhuisheng
Xuhuisheng lemon |
Mon, 25 Aug 2025 04:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A weakness has been identified in xuhuisheng lemon up to 1.13.0. This affects the function uploadImage of the file CmsArticleController.java of the component com.mossle.cms.web.CmsArticleController.uploadImage. This manipulation of the argument Upload causes unrestricted upload. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited. | |
Title | xuhuisheng lemon CmsArticleController.java uploadImage unrestricted upload | |
Weaknesses | CWE-284 CWE-434 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-08-25T03:32:06.413Z
Updated: 2025-08-25T15:31:01.987Z
Reserved: 2025-08-24T17:02:39.045Z
Link: CVE-2025-9406

No data.

Status : Received
Published: 2025-08-25T04:15:55.657
Modified: 2025-08-25T04:15:55.657
Link: CVE-2025-9406

No data.