The KFOX from KingFor has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privilege to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Metrics
Affected Vendors & Products
References
History
Mon, 12 May 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 12 May 2025 07:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The KFOX from KingFor has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privilege to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
Title | Kinfor KFOX - Arbitrary File Upload | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: twcert
Published: 2025-05-12T06:44:29.959Z
Updated: 2025-05-12T14:33:58.423Z
Reserved: 2025-05-12T01:49:34.360Z
Link: CVE-2025-4561

Updated: 2025-05-12T14:33:53.074Z

Status : Awaiting Analysis
Published: 2025-05-12T07:15:48.557
Modified: 2025-05-12T17:32:32.760
Link: CVE-2025-4561

No data.