VulnAI


EUVD-2025-208154

ID: EUVD-2025-208154

Severity: critical

CVSS v4: 9.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L)

CVSS v3: Not provided

CWE: None listed

Source: ENISA

Description

DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can result in Remote Code Execution. This issue was fixed in versions above 5.0.

Timestamps

References

No references provided.