Security Advisory

CVE-2025-1791

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-03-01 13:31:04
Last updated 2025-03-03 20:36:54
Assigner VulDB
State PUBLISHED

Description

A vulnerability has been found in Zorlan SkyCaiji 2.9 and classified as critical. This vulnerability affects the function fileAction of the file vendor/skycaiji/app/admin/controller/Tool.php. The manipulation of the argument save_data leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.