Security Advisory

CVE-2025-52130

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-08-25 00:00:00
Last updated 2025-08-26 15:29:58
Assigner mitre
State PUBLISHED

Description

File upload vulnerability in WebErpMesv2 1.17 in the app/Http/Controllers/FactoryController.php controller. This flaw allows an authenticated attacker to upload arbitrary files, including PHP scripts, which can be accessed via direct GET requests, potentially resulting in remote code execution (RCE) on the web server.