Metrics
Affected Vendors & Products
Sat, 15 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bdtask
Bdtask news365 Codecanyon Codecanyon news365 |
|
| Vendors & Products |
Bdtask
Bdtask news365 Codecanyon Codecanyon news365 |
Fri, 14 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in Bdtask/CodeCanyon News365 up to 7.0.3. This affects an unknown function of the file /admin/dashboard/profile. The manipulation of the argument profile_image/banner_image results in unrestricted upload. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Bdtask/CodeCanyon News365 profile unrestricted upload | |
| Weaknesses | CWE-284 CWE-434 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-11-14T21:02:06.306Z
Updated: 2025-11-14T21:20:33.280Z
Reserved: 2025-11-14T12:59:10.260Z
Link: CVE-2025-13185
Updated: 2025-11-14T21:20:29.104Z
Status : Awaiting Analysis
Published: 2025-11-14T21:15:44.153
Modified: 2025-11-18T14:06:55.963
Link: CVE-2025-13185
No data.