Code Injection Vulnerability in Lin-CMS-TP5 by ChenJinchuang
CVE-2025-15129
Key Information:
- Vendor
Chenjinchuang
- Status
- Vendor
- CVE Published:
- 28 December 2025
Badges
What is CVE-2025-15129?
A vulnerability has been identified in Lin-CMS-TP5, specifically affecting the file upload functionality within the application/library/file/LocalUploader.php component. This flaw can be exploited through manipulation of the File argument, enabling remote code execution. The issue was highlighted in an issue report submitted to the project maintainers; however, a response has yet to be documented. Attackers can exploit this vulnerability to execute arbitrary code on the server, posing significant security risks.
Affected Version(s)
Lin-CMS-TP5 0.3.0
Lin-CMS-TP5 0.3.1
Lin-CMS-TP5 0.3.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
