Metrics
Affected Vendors & Products
Mon, 14 Apr 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 14 Apr 2025 05:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in Lingxing ERP 2. It has been classified as critical. This affects an unknown part of the file /Api/TinyMce/UploadAjax.ashx. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | Lingxing ERP UploadAjax.ashx unrestricted upload | |
Weaknesses | CWE-284 CWE-434 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-04-14T14:29:06.536Z
Reserved: 2025-04-13T22:14:06.588Z
Link: CVE-2025-3552

Updated: 2025-04-14T14:27:57.637Z

Status : Awaiting Analysis
Published: 2025-04-14T06:15:16.440
Modified: 2025-04-15T18:39:27.967
Link: CVE-2025-3552

No data.