CVE-2025-51056 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write to arbitrary filesystem paths by exploiti…
High CVSS: 8.2

CVE-2025-51056

An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write to arbitrary filesystem paths by exploiting the insecure 'uploadPreviews()' custom function in '/api_vedo/colorways_preview', ultimately resulting in remote code execution (RCE).
Vendor
Vedo Suite Project
Product
Vedo Suite
CWE
CWE-434
Yayın Tarihi
2025-08-06 21:15:30
Güncelleme
2025-10-09 17:36:18
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar