Unrestricted File Upload Vulnerability in BiggiDroid Simple PHP CMS 1.0
CVE-2025-15262
Key Information:
- Vendor
Biggidroid
- Status
- Vendor
- CVE Published:
- 30 December 2025
Badges
What is CVE-2025-15262?
A vulnerability has been identified in the BiggiDroid Simple PHP CMS version 1.0, specifically within the Site Logo Handler found in the /admin/edit.php file. This flaw permits an attacker to manipulate image arguments, resulting in unrestricted file uploads. Such exploitation could allow remote attackers to upload malicious files to the server, potentially leading to further compromise of the web application and its underlying infrastructure. The exploit has been publicly released, increasing the risk of such attacks.
Affected Version(s)
Simple PHP CMS 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
