CVE-2025-13198

A vulnerability has been found in DouPHP up to 1.8 Release 20251022. This impacts an unknown function of the file upload/include/file.class.php. The manipulation of the argument File leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Configurations

No configuration.

History

15 Nov 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-15 09:15

Updated : 2025-11-18 14:06


NVD link : CVE-2025-13198

Mitre link : CVE-2025-13198

CVE.ORG link : CVE-2025-13198


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control

CWE-434

Unrestricted Upload of File with Dangerous Type