High severity7.5NVD Advisory· Published Mar 3, 2023· Updated Jun 17, 2026
CVE-2023-25402
CVE-2023-25402
Description
CleverStupidDog yf-exam 1.8.0 is vulnerable to File Upload. There is no restriction on the suffix of the uploaded file, resulting in any file upload.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:yf-exam_project:yf-exam:1.8.0:*:*:*:*:*:*:*
=1.8.0+ 1 more
- (no CPE)range: =1.8.0
- (no CPE)
Patches
Vulnerability mechanics
References
2- github.com/CleverStupidDog/yf-exam/issues/1nvdExploitIssue TrackingThird Party Advisory
- github.com/Fw-fW-fw/UPDATE-CVE/blob/main/CVE-2023-25402nvdThird Party Advisory
News mentions
0No linked articles in our index yet.