CVE-2025-11436

MEDIUM

JhumanJ OpnForm <1.9.3 - Unrestricted Upload

Title source: llm
STIX 2.1

Description

A vulnerability was detected in JhumanJ OpnForm up to 1.9.3. Affected by this issue is some unknown functionality of the file /answer. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit is now public and may be used. The patch is identified as 95c3e23856465d202e6aec10bdb6ee0688b5305a. It is advisable to implement a patch to correct this issue.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
https://vuldb.com/?id.327373
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.327373
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.666877

Scores

CVSS v3 6.3
EPSS 0.0005
EPSS Percentile 14.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284 CWE-434
Status published
Products (1)
jhumanj/opnform < 1.9.3
Published Oct 08, 2025
Tracked Since Feb 18, 2026