CVE-2025-51056
Last modified
CVE-2025-51056 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write to arbitrary filesystem paths by exploiting the insecure 'uploadPreviews()' custom function in '/api_vedo/colorways_preview', ultimately resulting in remote code execution (RCE).. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write to arbitrary filesystem paths by exploiting the insecure 'uploadPreviews()' custom function in '/api_vedo/colorways_preview', ultimately resulting in remote code execution (RCE).
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vedo Suite Project | Vedo Suite | 2024.17 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-51056?
How severe is CVE-2025-51056?
How do I fix CVE-2025-51056?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-51045Phpgurukul Pre-School Enrollment System 1.0 contains a SQL i…6.5
- CVE-2025-5105A vulnerability was found in TOZED ZLT W51 up to 1.4.2 and c…7.3
- CVE-2025-51052A path traversal vulnerability in Vedo Suite 2024.17 allows …6.5
- CVE-2025-51053A Cross-site scripting (XSS) vulnerability in /api_vedo/ in …6.1
- CVE-2025-51054Vedo Suite 2024.17 is vulnerable to Incorrect Access Control…6.5
- CVE-2025-51055Insecure Data Storage of credentials has been found in /api_…8.6
- CVE-2025-51057A local file inclusion (LFI) vulnerability in Vedo Suite ver…6.5
- CVE-2025-51058Bottinelli Informatical Vedo Suite 2024.17 is vulnerable to …6.5
- CVE-2025-5106A vulnerability was found in Fujian Kelixun 1.0. It has been…7.3
- CVE-2025-51060An issue was discovered in CPUID cpuz.sys 1.0.5.4. An attack…6.5
- CVE-2025-5107A vulnerability was found in Fujian Kelixun 1.0. It has been…9.8
- CVE-2025-5108A vulnerability was found in zongzhige ShopXO 6.5.0. It has …9.8
Are you affected by CVE-2025-51056?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
