Unrestricted File Upload Vulnerability in Chaty Pro by NotFound
CVE-2025-26776
10CRITICAL
Key Information:
- Vendor
- Notfound
- Status
- Chaty Pro
- Vendor
- CVE Published:
- 22 February 2025
Summary
The NotFound Chaty Pro plugin is susceptible to an unrestricted file upload vulnerability that allows users to upload dangerous file types. This flaw enables the potential for a web shell to be placed on the server, leading to unauthorized access and control over the affected web application. The vulnerability impacts all versions of Chaty Pro from n/a through 3.3.3, making it crucial for users to update their installations promptly to safeguard against potential threats.
Affected Version(s)
Chaty Pro <= 3.3.3
References
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
luc (Patchstack Alliance)