Metrics
Affected Vendors & Products
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 11 Feb 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Feb 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability, which was classified as critical, was found in Lumsoft ERP 8. Affected is the function DoUpload/DoWebUpload of the file /Api/FileUploadApi.ashx. The manipulation of the argument file leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Title | Lumsoft ERP FileUploadApi.ashx DoWebUpload unrestricted upload | |
| Weaknesses | CWE-284 CWE-434 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-02-11T00:31:04.757Z
Updated: 2025-02-18T18:08:54.776Z
Reserved: 2025-02-10T08:14:54.672Z
Link: CVE-2025-1165
Updated: 2025-02-11T05:58:43.674Z
Status : Awaiting Analysis
Published: 2025-02-11T01:15:09.947
Modified: 2025-02-18T18:15:30.530
Link: CVE-2025-1165
No data.