Medium severity4.8NVD Advisory· Published Feb 21, 2025· Updated Jun 17, 2026
CVE-2025-25766
CVE-2025-25766
Description
An arbitrary file upload vulnerability in the component /file/savefile.do of MRCMS v3.1.2 allows attackers to execute arbitrary code via uploading a crafted .jsp file.
Affected products
3Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.