Unrestricted File Upload Vulnerability in BiggiDroid Simple PHP CMS 1.0
CVE-2025-15262

5.1MEDIUM

Key Information:

Vendor

Biggidroid

Vendor
CVE Published:
30 December 2025

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2025-15262?

A vulnerability has been identified in the BiggiDroid Simple PHP CMS version 1.0, specifically within the Site Logo Handler found in the /admin/edit.php file. This flaw permits an attacker to manipulate image arguments, resulting in unrestricted file uploads. Such exploitation could allow remote attackers to upload malicious files to the server, potentially leading to further compromise of the web application and its underlying infrastructure. The exploit has been publicly released, increasing the risk of such attacks.

Affected Version(s)

Simple PHP CMS 1.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

heishanyao (VulDB User)
.
CVE-2025-15262 : Unrestricted File Upload Vulnerability in BiggiDroid Simple PHP CMS 1.0