A vulnerability classified as problematic has been found in enilu web-flash 1.0. This affects the function fileService.upload of the file src/main/java/cn/enilu/flash/api/controller/FileController/upload of the component File Upload. The manipulation of the argument File leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
History

Mon, 09 Jun 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Enilu
Enilu web-flash
CPEs cpe:2.3:a:enilu:web-flash:1.0:*:*:*:*:*:*:*
Vendors & Products Enilu
Enilu web-flash

Tue, 03 Jun 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 03 Jun 2025 19:45:00 +0000

Type Values Removed Values Added
Description A vulnerability classified as problematic has been found in enilu web-flash 1.0. This affects the function fileService.upload of the file src/main/java/cn/enilu/flash/api/controller/FileController/upload of the component File Upload. The manipulation of the argument File leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Title enilu web-flash File Upload upload fileService.upload cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-06-03T19:31:20.057Z

Updated: 2025-06-03T20:15:24.579Z

Reserved: 2025-06-03T09:39:28.680Z

Link: CVE-2025-5523

cve-icon Vulnrichment

Updated: 2025-06-03T20:13:55.925Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-03T20:15:22.387

Modified: 2025-06-09T15:12:42.317

Link: CVE-2025-5523

cve-icon Redhat

No data.