Vulnerability Description
An arbitrary file upload vulnerability in the plugin installation feature of YZNCMS v2.0.1 allows attackers to execute arbitrary code via uploading a crafted Zip file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yzncms | Yzncms | 2.0.1 |
Related Weaknesses (CWE)
References
- http://yzncms.comNot Applicable
- https://gitee.com/ken678/YZNCMSProduct
- https://github.com/Ka7arotto/YZNCMS/blob/main/yzncms-upload.mdExploit
FAQ
What is CVE-2025-25791?
CVE-2025-25791 is a vulnerability with a CVSS score of 4.4 (MEDIUM). An arbitrary file upload vulnerability in the plugin installation feature of YZNCMS v2.0.1 allows attackers to execute arbitrary code via uploading a crafted Zip file.
How severe is CVE-2025-25791?
CVE-2025-25791 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-25791?
Check the references section above for vendor advisories and patch information. Affected products include: Yzncms Yzncms.