CVE-2025-45752

A vulnerability in SeedDMS 6.0.32 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the zip import functionality in the Extension Manager.
Configurations

No configuration.

History

22 May 2025, 19:15

Type Values Removed Values Added
References () https://www.simonjuguna.com/cve-2025-45752-authenticated-remote-code-execution-vulnerability-in-seeddms-v6-0-32/ - () https://www.simonjuguna.com/cve-2025-45752-authenticated-remote-code-execution-vulnerability-in-seeddms-v6-0-32/ -
CWE CWE-94
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
Summary
  • (es) Una vulnerabilidad en SeedDMS 6.0.32 permite a un atacante con privilegios de administrador ejecutar código PHP arbitrario explotando la funcionalidad de importación zip en el Administrador de extensiones.

21 May 2025, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-21 19:16

Updated : 2025-05-22 19:15


NVD link : CVE-2025-45752

Mitre link : CVE-2025-45752

CVE.ORG link : CVE-2025-45752


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')