Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-5356 | An arbitrary file upload vulnerability in the plugin installation feature of YZNCMS v2.0.1 allows attackers to execute arbitrary code via uploading a crafted Zip file. |
Mon, 07 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yzncms
Yzncms yzncms |
|
| CPEs | cpe:2.3:a:yzncms:yzncms:2.0.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Yzncms
Yzncms yzncms |
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Mar 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-77 | |
| Metrics |
cvssV3_1
|
Wed, 26 Feb 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An arbitrary file upload vulnerability in the plugin installation feature of YZNCMS v2.0.1 allows attackers to execute arbitrary code via uploading a crafted Zip file. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-03T17:21:33.067Z
Reserved: 2025-02-07T00:00:00.000Z
Link: CVE-2025-25791
Updated: 2025-03-03T17:21:27.881Z
Status : Analyzed
Published: 2025-02-26T15:15:27.100
Modified: 2025-04-07T18:52:59.103
Link: CVE-2025-25791
No data.
OpenCVE Enrichment
No data.
EUVD