A vulnerability has been found in DouPHP up to 1.8 Release 20251022. This impacts an unknown function of the file upload/include/file.class.php. The manipulation of the argument File leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
History

Sat, 15 Nov 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Douphp
Douphp douphp
Vendors & Products Douphp
Douphp douphp

Sat, 15 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in DouPHP up to 1.8 Release 20251022. This impacts an unknown function of the file upload/include/file.class.php. The manipulation of the argument File leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Title DouPHP file.class.php unrestricted upload
Weaknesses CWE-284
CWE-434
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-11-15T09:02:07.001Z

Updated: 2025-11-15T09:02:07.001Z

Reserved: 2025-11-14T16:12:45.375Z

Link: CVE-2025-13198

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-15T09:15:42.177

Modified: 2025-11-15T09:15:42.177

Link: CVE-2025-13198

cve-icon Redhat

No data.