CVE-2025-7100
Last modified
CVE-2025-7100 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability was found in BoyunCMS up to 1.4.20 and classified as critical. Affected by this issue is some unknown functionality of the file /application/user/controller/Index.php. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
A vulnerability was found in BoyunCMS up to 1.4.20 and classified as critical. Affected by this issue is some unknown functionality of the file /application/user/controller/Index.php. The manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Boyuncms Project | Boyuncms | >= 1.4, <= 1.4.20 |
References
- https://vuldb.com/?ctiid.315014Permissions Required, VDB Entry
- https://vuldb.com/?id.315014Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.604455Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-7100?
How severe is CVE-2025-7100?
How do I fix CVE-2025-7100?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-7099A vulnerability has been found in BoyunCMS up to 1.21 on PHP…5.9
- CVE-2025-70994Yadea T5 Electric Bicycles (models manufactured in/after 202…7.3
- CVE-2025-70995An issue in Aranda Service Desk Web Edition (ASDK API 8.6) a…8.8
- CVE-2025-70997A vulnerability has been discovered in eladmin v2.7 and befo…6.5
- CVE-2025-70998UTT HiPER 810 / nv810v4 router firmware v1.5.0-140603 was di…9.8
- CVE-2025-70999A GPU device-ID validation flaw in the flow.cuda.get_device_…7.5
- CVE-2025-71000An issue in the flow.cuda.BoolTensor component of OneFlow v0…7.5
- CVE-2025-71001A segmentation violation in the flow.column_stack component …6.5
- CVE-2025-71002A floating-point exception (FPE) in the flow.column_stack co…6.5
- CVE-2025-71003An input validation vulnerability in the flow.arange() compo…7.5
- CVE-2025-71004A segmentation violation in the oneflow.logical_or component…6.5
- CVE-2025-71005A floating point exception (FPE) in the oneflow.view compone…6.5
Are you affected by CVE-2025-7100?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
