File Upload Vulnerability in WebErpMesv2 by SMEWebify
CVE-2025-52130

5.4MEDIUM

Key Information:

Vendor

SMEWebify

Vendor
CVE Published:
25 August 2025

What is CVE-2025-52130?

A file upload vulnerability exists in WebErpMesv2 1.17 that enables authenticated users to upload arbitrary files, including potentially malicious PHP scripts. This security flaw resides in the app/Http/Controllers/FactoryController.php file, allowing attackers to leverage GET requests for accessing the uploaded files. The exploitation of this vulnerability could lead to remote code execution on the affected web server, posing significant risks to data integrity and system security.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.