Vulnerability Description
An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write to arbitrary filesystem paths by exploiting the insecure 'uploadPreviews()' custom function in '/api_vedo/colorways_preview', ultimately resulting in remote code execution (RCE).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vedo Suite Project | Vedo Suite | 2024.17 |
Related Weaknesses (CWE)
References
- http://bottinelli.comBroken Link
- https://github.com/jacopoaugelli/vedo-suite-exploitsExploit
- https://github.com/jacopoaugelli/vedo-suite-exploitsExploit
FAQ
What is CVE-2025-51056?
CVE-2025-51056 is a vulnerability with a CVSS score of 8.2 (HIGH). An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write to arbitrary filesystem paths by exploiting the insecure 'uploadPreviews()' custo...
How severe is CVE-2025-51056?
CVE-2025-51056 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-51056?
Check the references section above for vendor advisories and patch information. Affected products include: Vedo Suite Project Vedo Suite.