Unrestricted File Upload Vulnerability in Youkefu by Zhangyanbo2007
CVE-2025-4258
Key Information:
- Vendor
Zhangyanbo2007
- Status
- Vendor
- CVE Published:
- 5 May 2025
Badges
What is CVE-2025-4258?
A significant vulnerability identified in Youkefu by Zhangyanbo2007 allows for unrestricted file uploads through the MediaController.java file. Specifically, the vulnerable function, Upload, accepts a manipulated imgFile argument, permitting remote attackers to upload malicious files. This exploit is publicly disclosed, making it imperative for users to apply necessary mitigations to protect their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
youkefu 4.0
youkefu 4.1
youkefu 4.2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
