VYPR
Unrated severityNVD Advisory· Published Jul 20, 2025· Updated Jul 21, 2025

harry0703 MoneyPrinterTurbo File Extension video.py upload_bgm_file unrestricted upload

CVE-2025-7895

Description

A vulnerability, which was classified as critical, was found in harry0703 MoneyPrinterTurbo up to 1.2.6. Affected is the function upload_bgm_file of the file app/controllers/v1/video.py of the component File Extension Handler. The manipulation of the argument File leads to unrestricted upload. It is possible to launch the attack remotely.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.