Filtered by vendor Xuhuisheng Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-9406 1 Xuhuisheng 1 Lemon 2025-08-25 6.3 Medium
A weakness has been identified in xuhuisheng lemon up to 1.13.0. This affects the function uploadImage of the file CmsArticleController.java of the component com.mossle.cms.web.CmsArticleController.uploadImage. This manipulation of the argument Upload causes unrestricted upload. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.