A vulnerability has been found in Zorlan SkyCaiji 2.9 and...
Moderate severity
Unreviewed
Published
Mar 1, 2025
to the GitHub Advisory Database
•
Updated Mar 1, 2025
Description
Published by the National Vulnerability Database
Mar 1, 2025
Published to the GitHub Advisory Database
Mar 1, 2025
Last updated
Mar 1, 2025
A vulnerability has been found in Zorlan SkyCaiji 2.9 and classified as critical. This vulnerability affects the function fileAction of the file vendor/skycaiji/app/admin/controller/Tool.php. The manipulation of the argument save_data leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
References