CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-1835: osuuu LightPicture Api.php upload unrestricted upload

5.3 CVSS

Description

A vulnerability has been found in osuuu LightPicture 1.2.2 and classified as critical. This vulnerability affects the function upload of the file /app/controller/Api.php. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. In osuuu LightPicture 1.2.2 wurde eine kritische Schwachstelle gefunden. Betroffen ist die Funktion upload der Datei /app/controller/Api.php. Mit der Manipulation des Arguments file mit unbekannten Daten kann eine unrestricted upload-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk passieren. Der Exploit steht zur öffentlichen Verfügung.

Classification

CVE ID: CVE-2025-1835

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.3

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Problem Types

Unrestricted Upload Improper Access Controls

Affected Products

Vendor: osuuu

Product: LightPicture

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 8.89% (scored less or equal to compared to others)

EPSS Date: 2025-03-31 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-1835
https://vuldb.com/?id.298102
https://vuldb.com/?ctiid.298102
https://vuldb.com/?submit.505007
https://github.com/sheratan4/cve/issues/1

Timeline