CVE-2025-2706
Last modified
CVE-2025-2706 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A vulnerability classified as critical was found in Digiwin ERP 5.0.1. Affected by this vulnerability is an unknown functionality of the file /Api/TinyMce/UploadAjaxAPI.ashx. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
A vulnerability classified as critical was found in Digiwin ERP 5.0.1. Affected by this vulnerability is an unknown functionality of the file /Api/TinyMce/UploadAjaxAPI.ashx. The manipulation of the argument File leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-2706?
How severe is CVE-2025-2706?
How do I fix CVE-2025-2706?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-27054Memory corruption while processing a malformed license file …7.8
- CVE-2025-27055Memory corruption during the image encoding process.7.8
- CVE-2025-27056Memory corruption during sub-system restart while processing…7.8
- CVE-2025-27057Transient DOS while handling beacon frames with invalid IE h…7.5
- CVE-2025-27058Memory corruption while processing packet data with exceedin…7.8
- CVE-2025-27059Memory corruption while performing SCM call.8.8
- CVE-2025-27060Memory corruption while performing SCM call with malformed i…8.8
- CVE-2025-27061Memory corruption whhile handling the subsystem failure memo…7.8
- CVE-2025-27062Memory corruption while handling client exceptions, allowing…7.8
- CVE-2025-27063Memory corruption during video playback when video session o…7.8
- CVE-2025-27064Information disclosure while registering commands from clien…6.1
- CVE-2025-27065Transient DOS while processing a frame with malformed shared…7.5
Are you affected by CVE-2025-2706?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
