Metrics
Affected Vendors & Products
Tue, 11 Feb 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 11 Feb 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability, which was classified as critical, was found in Lumsoft ERP 8. Affected is the function DoUpload/DoWebUpload of the file /Api/FileUploadApi.ashx. The manipulation of the argument file leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
Title | Lumsoft ERP FileUploadApi.ashx DoWebUpload unrestricted upload | |
Weaknesses | CWE-284 CWE-434 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-02-18T18:08:54.776Z
Reserved: 2025-02-10T08:14:54.672Z
Link: CVE-2025-1165

Updated: 2025-02-11T05:58:43.674Z

Status : Awaiting Analysis
Published: 2025-02-11T01:15:09.947
Modified: 2025-02-18T18:15:30.530
Link: CVE-2025-1165

No data.