mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-29 20:39:28 +02:00
1.4 KiB
1.4 KiB
CVE-2025-8841
Description
A vulnerability was identified in zlt2000 microservices-platform up to 6.0.0. Affected by this vulnerability is the function Upload of the file zlt-business/file-center/src/main/java/com/central/file/controller/FileController.java. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Es geht um die Funktion Upload der Datei zlt-business/file-center/src/main/java/com/central/file/controller/FileController.java. Dank Manipulation mit unbekannten Daten kann eine unrestricted upload-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung.
POC
Reference
- https://github.com/zlt2000/microservices-platform/issues/77
- https://github.com/zlt2000/microservices-platform/issues/77#issue-3264841808