HuoCMS V3.5.1 has a File Upload Vulnerability. An attacker can exploit this flaw to bypass whitelist restrictions and craft malicious files with specific suffixes, thereby gaining control of the server.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://github.com/yggcwhat/test2/blob/main/README.md | exploit third party advisory |
https://github.com/yggcwhat/CVE-2025-46080/ | exploit third party advisory |