cvelist/2025/3xxx/CVE-2025-3551.json
2025-04-25 14:00:33 +00:00

119 lines
4.3 KiB
JSON

{
"data_version": "4.0",
"data_type": "CVE",
"data_format": "MITRE",
"CVE_data_meta": {
"ID": "CVE-2025-3551",
"ASSIGNER": "cna@vuldb.com",
"STATE": "PUBLIC"
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "** DISPUTED ** A vulnerability was found in Lingxing ERP 2 and classified as critical. Affected by this issue is the function DoUpload of the file /Api/FileUpload.ashx?method=DoUpload. The manipulation of the argument File leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment."
},
{
"lang": "deu",
"value": "** DISPUTED ** Eine Schwachstelle wurde in Lingxing ERP 2 gefunden. Sie wurde als kritisch eingestuft. Dies betrifft die Funktion DoUpload der Datei /Api/FileUpload.ashx?method=DoUpload. Mit der Manipulation des Arguments File mit unbekannten Daten kann eine unrestricted upload-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk passieren. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung. Bisher konnte die Existenz der vermeintlichen Schwachstelle noch nicht eindeutig nachgewiesen werden."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Unrestricted Upload",
"cweId": "CWE-434"
}
]
},
{
"description": [
{
"lang": "eng",
"value": "Improper Access Controls",
"cweId": "CWE-284"
}
]
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "Lingxing",
"product": {
"product_data": [
{
"product_name": "ERP",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "2"
}
]
}
}
]
}
}
]
}
},
"references": {
"reference_data": [
{
"url": "https://vuldb.com/?id.304592",
"refsource": "MISC",
"name": "https://vuldb.com/?id.304592"
},
{
"url": "https://vuldb.com/?ctiid.304592",
"refsource": "MISC",
"name": "https://vuldb.com/?ctiid.304592"
},
{
"url": "https://vuldb.com/?submit.547878",
"refsource": "MISC",
"name": "https://vuldb.com/?submit.547878"
},
{
"url": "https://github.com/666lail/report/blob/main/tmp/fileUpload_1.md",
"refsource": "MISC",
"name": "https://github.com/666lail/report/blob/main/tmp/fileUpload_1.md"
}
]
},
"credits": [
{
"lang": "en",
"value": "207556249 (VulDB User)"
}
],
"impact": {
"cvss": [
{
"version": "3.1",
"baseScore": 7.3,
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"baseSeverity": "HIGH"
},
{
"version": "3.0",
"baseScore": 7.3,
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"baseSeverity": "HIGH"
},
{
"version": "2.0",
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
}
]
}
}