Metrics
Affected Vendors & Products
Fri, 03 Oct 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ideacms:ideacms:*:*:*:*:*:*:*:* |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 06 May 2025 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 May 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability, which was classified as critical, was found in IdeaCMS up to 1.6. Affected is the function saveUpload. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Title | IdeaCMS saveUpload unrestricted upload | |
| Weaknesses | CWE-284 CWE-434 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-05-05T22:00:11.189Z
Updated: 2025-05-06T02:50:04.646Z
Reserved: 2025-05-05T12:00:06.710Z
Link: CVE-2025-4291
Updated: 2025-05-06T02:50:00.927Z
Status : Analyzed
Published: 2025-05-05T22:15:17.550
Modified: 2025-10-03T14:50:51.930
Link: CVE-2025-4291
No data.