← volver
CVE-2025-8344

openviglet shio ShStaticFileAPI.java shStaticFileUpload unrestricted upload

CVSS 5.3 MEDIUMEPSS 0.3%CWE-284CWE-434
A vulnerability classified as critical has been found in openviglet shio up to 0.3.8. Affected is the function shStaticFileUpload of the file shio-app/src/main/java/com/viglet/shio/api/staticfile/ShStaticFileAPI.java. The manipulation of the argument filename leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
openviglet · shio

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →