Unrated severityNVD Advisory· Published Jul 20, 2025· Updated Jul 21, 2025
harry0703 MoneyPrinterTurbo File Extension video.py upload_bgm_file unrestricted upload
CVE-2025-7895
Description
A vulnerability, which was classified as critical, was found in harry0703 MoneyPrinterTurbo up to 1.2.6. Affected is the function upload_bgm_file of the file app/controllers/v1/video.py of the component File Extension Handler. The manipulation of the argument File leads to unrestricted upload. It is possible to launch the attack remotely.
Affected products
1- Range: 1.2.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.