ZeroHour

CVE-2025-51056

PoC
CVSS 3.1
8.2 high
EPSS
<1%p43
Published
()
Modified
Description

An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write to arbitrary filesystem paths by exploiting the insecure 'uploadPreviews()' custom function in '/api_vedo/colorways_preview', ultimately resulting in remote code execution (RCE).

Vendors
vedo suite project
Products
vedo suite
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.