CVE-2025-3593 | ZHENFENG13/code-projects My-Blog-layui 1.0 /admin/upload/authorImg/ upload File unrestricted upload
A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been rated as critical. This affects the function Upload of the file /admin/upload/authorImg/. Performing manipulation of the argument File results in unrestricted upload.
This vulnerability is reported as CVE-2025-3593. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.