Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Justinsecure

#43829of 56,328
6.5Total CVSS
Vulnerabilities · 1
PT-2025-31952
6.5
2025-08-05
Unknown · Twisted Web · CVE-2025-50688
**Name of the Vulnerable Software and Affected Versions** TwistedWeb version 14.0.0 **Description** A command injection issue exists in TwistedWeb due to improper input sanitization in the file upload functionality. An attacker can exploit this by sending a specially crafted HTTP PUT request to upload a malicious file, such as a reverse shell script. Once uploaded, the attacker can trigger the execution of arbitrary commands on the target system, potentially leading to remote code execution and escalation of privileges depending on the privileges of the web server process. The attack can be conducted remotely. **Recommendations** Update TwistedWeb to a newer version that contains a fix for this issue. As a temporary workaround, restrict file upload functionality to trusted users only.