SourceCodester Company Website CMS 1.0 contains a file upload vulnerability via the "Create Services" file /dashboard/Services.
References
| Link | Resource |
|---|---|
| https://github.com/fupanc-w1n/fupanc/blob/main/php/CVE-2025-29708.md | Third Party Advisory |
| https://github.com/fupanc-w1n/fupanc/blob/main/php/Company%20Website%20CMS1.md | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-04-16 21:15
Updated : 2025-04-23 16:33
NVD link : CVE-2025-29708
Mitre link : CVE-2025-29708
CVE.ORG link : CVE-2025-29708
JSON object : View
Products Affected
torrahclef
- company_website_cms
CWE
CWE-73
External Control of File Name or Path
