Vulnerability Description
A vulnerability was identified in h-moses moga-mall up to 392d631a5ef15962a9bddeeb9f1269b9085473fa. This vulnerability affects the function addProduct of the file src/main/java/com/ms/product/controller/PmsProductController.java. Such manipulation of the argument objectName leads to unrestricted upload. The attack may be performed from remote. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/zyhzheng500-maker/cve/blob/main/moga-mall%E4%BB%BB%E6%84%8F%E
- https://vuldb.com/?ctiid.338529
- https://vuldb.com/?id.338529
- https://vuldb.com/?submit.721988
FAQ
What is CVE-2025-15152?
CVE-2025-15152 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A vulnerability was identified in h-moses moga-mall up to 392d631a5ef15962a9bddeeb9f1269b9085473fa. This vulnerability affects the function addProduct of the file src/main/java/com/ms/product/controll...
How severe is CVE-2025-15152?
CVE-2025-15152 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-15152?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.