← voltar
CVE-2025-8344

openviglet shio ShStaticFileAPI.java shStaticFileUpload unrestricted upload

CVSS 5.3 MEDIUMEPSS 0.3%CWE-284CWE-434
A vulnerability classified as critical has been found in openviglet shio up to 0.3.8. Affected is the function shStaticFileUpload of the file shio-app/src/main/java/com/viglet/shio/api/staticfile/ShStaticFileAPI.java. The manipulation of the argument filename leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Produtos afetados
openviglet · shio

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →