Security Advisory

CVE-2025-9406

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-08-25 03:32:06
Last updated 2025-08-25 15:31:01
Assigner VulDB
State PUBLISHED

Description

A weakness has been identified in xuhuisheng lemon up to 1.13.0. This affects the function uploadImage of the file CmsArticleController.java of the component com.mossle.cms.web.CmsArticleController.uploadImage. This manipulation of the argument Upload causes unrestricted upload. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.