CVE-2025-4768
Last modified
CVE-2025-4768 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A vulnerability classified as critical has been found in feng_ha_ha/megagao ssm-erp and production_ssm 1.0. This affects the function uploadPicture of the file PictureServiceImpl.java. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
A vulnerability classified as critical has been found in feng_ha_ha/megagao ssm-erp and production_ssm 1.0. This affects the function uploadPicture of the file PictureServiceImpl.java. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is distributed under two entirely different names.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-4768?
How severe is CVE-2025-4768?
How do I fix CVE-2025-4768?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-47674Cross-Site Request Forgery (CSRF) vulnerability in Credova F…4.3
- CVE-2025-47675Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-47676Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-47677Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-47678Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2025-47679Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-47680Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2025-47681Cross-Site Request Forgery (CSRF) vulnerability in Ability, …4.3
- CVE-2025-47682Improper Neutralization of Special Elements used in an SQL C…9.8
- CVE-2025-47683Deserialization of Untrusted Data vulnerability in Florent M…7.2
- CVE-2025-47684Cross-Site Request Forgery (CSRF) vulnerability in Smaily Sm…5.4
- CVE-2025-47685Cross-Site Request Forgery (CSRF) vulnerability in Moloni Co…7.1
Are you affected by CVE-2025-4768?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
