CVE-2025-2671 - Yue Lao Blind Box Unrestricted File Upload Vulnerability

CVE ID : CVE-2025-2671 Published : March 23, 2025, 10:15 p.m. | 59 minutes ago Description : A vulnerability was found in Yue Lao Blind Box 月老盲盒 up to 4.0. It has been declared as critical. This vulnerability affects the function base64image of the file /app/controller/Upload.php. The manipulation of the argument data leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Mär 24, 2025 - 00:15
 0  0
CVE-2025-2671 - Yue Lao Blind Box Unrestricted File Upload Vulnerability
CVE ID : CVE-2025-2671
Published : March 23, 2025, 10:15 p.m. | 59 minutes ago
Description : A vulnerability was found in Yue Lao Blind Box 月老盲盒 up to 4.0. It has been declared as critical. This vulnerability affects the function base64image of the file /app/controller/Upload.php. The manipulation of the argument data leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...