VYPR
Critical severity9.9OSV Advisory· Published Jun 27, 2025· Updated Jun 17, 2026

CVE-2025-52207

CVE-2025-52207

Description

PBXCoreREST/Controllers/Files/PostController.php in MikoPBX through 2024.1.114 allows uploading a PHP script to an arbitrary directory.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Mikopbx/CoreOSV2 versions
    2019.4.5, 2019.4.53, 2020.1.124, …+ 1 more
    • (no CPE)range: 2019.4.5, 2019.4.53, 2020.1.124, …
    • (no CPE)range: <=2024.1.114
  • Mikopbx/MikoPBXllm-fuzzy
    Range: <=2024.1.114

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.