ZeroHour

CVE-2025-46080

PoC ×2
CVSS 3.1
5.3 medium
EPSS
<1%p35
Published
()
Modified
Description

HuoCMS V3.5.1 has a File Upload Vulnerability. An attacker can exploit this flaw to bypass whitelist restrictions and craft malicious files with specific suffixes, thereby gaining control of the server.

Vendors
huocms
Products
huocms
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.