9.1
CVE-2025-65473
- EPSS 0.12%
- Veröffentlicht 11.12.2025 00:00:00
- Zuletzt bearbeitet 15.12.2025 19:28:47
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An arbitrary file rename vulnerability in the /admin/filer.php component of EasyImages 2.0 v2.8.6 and below allows attackers with Administrator privileges to execute arbitrary code via injecting a crafted payload into an uploaded file name.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Easyimages2.0 Project ≫ Easyimages2.0 Version <= 2.8.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.311 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.1 | 2.3 | 6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
CWE-73 External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.