CVE-2025-25765
MEDIUMDescription
MRCMS v3.1.2 was discovered to contain an arbitrary file write vulnerability via the component /file/save.do.
Is your site exposed to CVE-2025-25765?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| mrcms | mrcms |
References
Frequently Asked Questions
What is CVE-2025-25765? +
How severe is CVE-2025-25765? +
What products are affected by CVE-2025-25765? +
How do I check if I'm vulnerable to CVE-2025-25765? +
Related Vulnerabilities
MRCMS 3.1.2 contains a SQL injection vulnerability via the RID parameter in /admin/article/delete.do.
MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not filtered.
SQL Injection vulnerability in MRCMS v3.1.2 allows attackers to run arbitrary system commands via the status parameter.
MRCMS v3.1.2 was discovered to contain a server-side template injection (SSTI) vulnerability in the component \servlet\DispatcherServlet.java. This vulnerability allows attackers …
A vulnerability has been found in MRCMS 3.1.2 and classified as critical. This vulnerability affects the function delete of the …
MRCMS 3.0 contains a Cross-Site Scripting (XSS) vulnerability via /admin/system/saveinfo.do.