Arbitrary File Write Vulnerability in MRCMS by MRCMS Team
CVE-2025-25765
4MEDIUM
What is CVE-2025-25765?
An arbitrary file write vulnerability exists in MRCMS v3.1.2 that could allow an attacker to save files to any location on the server through the /file/save.do component. This flaw could be exploited to manipulate files on the server, potentially leading to unauthorized access, data breach, or further exploitation of the server environment.
References
CVSS V3.1
Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved