Unrestricted File Upload Vulnerability in newbee-mall Product by newbee
CVE-2025-4259
Summary
A vulnerability has been identified in the newbee-mall product, specifically within the Upload function of the UploadController.java file. This flaw allows attackers to manipulate file arguments, leading to unrestricted file uploads. The implications of such a vulnerability are significant, as it enables unauthorized users to upload malicious files onto the server, potentially compromising the system's integrity. This exploit can be executed remotely, making it especially dangerous. Given that the product does not utilize versioning, it is challenging to determine the specifics of affected or unaffected releases, heightening the urgency for users to address this risk promptly.
Affected Version(s)
newbee-mall 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved