VulnerabilityAnalyzed
CVE-2025-15423
A vulnerability has been found in EmpireSoft EmpireCMS up to 8.0.
LOW 2.1EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability has been found in EmpireSoft EmpireCMS up to 8.0. Impacted is the function CheckSaveTranFiletype of the file e/class/connect.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- CVSS 4.0
- 2.1 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.36% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284, CWE-434
- Affected
- phome/empirecms
- Source
- cna@vuldb.com
References
- https://note-hxlab.wetolink.com/share/28QXRLje7Uz1Exploit, Third Party Advisory
- https://note-hxlab.wetolink.com/share/28QXRLje7Uz1#-span--strong-proof-of-concept---strong---span-Exploit, Third Party Advisory
- https://vuldb.com/?ctiid.339345Permissions Required, VDB Entry
- https://vuldb.com/?id.339345Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.721346Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.