CVE-2025-9406

MEDIUM

xuhuisheng lemon <1.13.0 - Unrestricted Upload

Title source: llm
STIX 2.1

Description

A weakness has been identified in xuhuisheng lemon up to 1.13.0. This affects the function uploadImage of the file CmsArticleController.java of the component com.mossle.cms.web.CmsArticleController.uploadImage. This manipulation of the argument Upload causes unrestricted upload. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.321242
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.321242
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.633593
Exploit, Issue Tracking issue-tracking
https://github.com/xuhuisheng/lemon/issues/212
Exploit, Issue Tracking exploit issue-tracking
https://github.com/xuhuisheng/lemon/issues/212#issue-3317490086

Scores

CVSS v3 6.3
EPSS 0.0008
EPSS Percentile 22.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284 CWE-434
Status published
Products (1)
mossle/lemon < 1.13.0
Published Aug 25, 2025
Tracked Since Feb 18, 2026