CVE-2025-25791

CVSS 3.1 Score 4.4 of 10 (medium)

Details

Published Feb 26, 2025
Updated: Mar 3, 2025
CWE ID 77

Summary

CVE-2025-25791 is an arbitrary file upload vulnerability affecting YZNCMS v2.0.1. An attacker can exploit this weakness by uploading a specially crafted Zip file through the plugin installation feature. Successful exploitation grants the attacker the ability to execute arbitrary code on the targeted system, posing a significant security risk. YZNCMS users are advised to update their installations to the latest version to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share