CVE-2025-7917

WinMatrix3 Web package developed by Simopro Technology has an Arbitrary File Upload vulnerability, allowing remote attackers with administrator privileges to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Configurations

No configuration.

History

22 Jul 2025, 13:06

Type Values Removed Values Added
Summary
  • (es) El paquete web WinMatrix3 desarrollado por Simopro Technology tiene una vulnerabilidad de carga de archivos arbitraria, que permite a atacantes remotos con privilegios de administrador cargar y ejecutar puertas traseras de shell web, lo que permite la ejecución de código arbitrario en el servidor.

21 Jul 2025, 07:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

21 Jul 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-21 06:15

Updated : 2025-07-22 13:06


NVD link : CVE-2025-7917

Mitre link : CVE-2025-7917

CVE.ORG link : CVE-2025-7917


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type