PT-2025-15701 · Verydows · Verydows

·

CVE-2025-29394

·

Published

2025-04-09

·

Updated

2025-04-10

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: verydows version 2.0
Description: The issue is related to insecure permissions, allowing a remote attacker to execute arbitrary code by uploading a specific file type. This can be achieved through the action of loading a particular type of file, which is not further specified.
Recommendations: For verydows version 2.0, consider restricting access to file uploads until a fix is available, or apply specific configuration changes to mitigate the risk of arbitrary code execution.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-29394

Affected Products

Verydows