CVE-2025-46080
MEDIUMHuoCMS V3.5.1 - Unrestricted Upload of File with Dangerous Type via Whitelist Bypass
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-46080. PoCs published by yggcwhat.
AI-analyzed exploit summary This PoC demonstrates an arbitrary file rename vulnerability in HuoCMS <= V3.5.1, allowing an attacker to bypass suffix whitelist restrictions and achieve remote code execution by renaming a malicious file to a PHP extension.
Description
HuoCMS V3.5.1 has a File Upload Vulnerability. An attacker can exploit this flaw to bypass whitelist restrictions and craft malicious files with specific suffixes, thereby gaining control of the server.
Exploits (1)
This PoC demonstrates an arbitrary file rename vulnerability in HuoCMS <= V3.5.1, allowing an attacker to bypass suffix whitelist restrictions and achieve remote code execution by renaming a malicious file to a PHP extension.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N