CVE-2025-4291

MEDIUM

IdeaCMS <1.6 - Unrestricted Upload

Title source: llm

Description

A vulnerability, which was classified as critical, was found in IdeaCMS up to 1.6. Affected is the function saveUpload. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Exploits (1)

gitee 423 stars
by ideacms_admin · phpwriteup
https://gitee.com/ideacms/ideacms/issues/IC32SB

Scores

CVSS v3 6.3
EPSS 0.0034
EPSS Percentile 56.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-284 CWE-434
Status published
Products (1)
ideacms/ideacms < 1.6
Published May 05, 2025
Tracked Since Feb 18, 2026