Unrestricted File Upload Vulnerability in xnx3 Wangmarket by xnx3
CVE-2025-15415
Key Information:
- Vendor
Xnx3
- Status
- Vendor
- CVE Published:
- 1 January 2026
Badges
What is CVE-2025-15415?
A vulnerability exists in the xnx3 Wangmarket product, specifically in the uploadImage function of the XML File Handler component. This flaw permits attackers to exploit the argument 'image' to achieve unrestricted file uploads, which could lead to remote exploitation. Despite early notification of this vulnerability, the vendor has not provided a response. The public disclosure amplifies the risk as this flaw can be easily exploited by malicious actors.
Affected Version(s)
wangmarket 6.0
wangmarket 6.1
wangmarket 6.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
