Vulnerability Description
PBXCoreREST/Controllers/Files/PostController.php in MikoPBX through 2024.1.114 allows uploading a PHP script to an arbitrary directory.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/mikopbx/Core/commit/3ee785429d3f1b33c9ab387ef4221127c9b8c5f3
- https://www.mikopbx.com/
FAQ
What is CVE-2025-52207?
CVE-2025-52207 is a vulnerability with a CVSS score of 9.9 (CRITICAL). PBXCoreREST/Controllers/Files/PostController.php in MikoPBX through 2024.1.114 allows uploading a PHP script to an arbitrary directory.
How severe is CVE-2025-52207?
CVE-2025-52207 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-52207?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.