An issue was discovered in MediaCrush thru 1.0.1 allowing remote unauthenticated attackers to upload arbitrary files of any size to the /upload endpoint.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-434 | |
| Metrics |
cvssV3_1
|
Wed, 04 Feb 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mediacrush
Mediacrush mediacrush |
|
| Vendors & Products |
Mediacrush
Mediacrush mediacrush |
Tue, 03 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in MediaCrush thru 1.0.1 allowing remote unauthenticated attackers to upload arbitrary files of any size to the /upload endpoint. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-02-03T00:00:00.000Z
Updated: 2026-02-04T16:10:51.725Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-61506
Updated: 2026-02-04T16:10:45.957Z
Status : Awaiting Analysis
Published: 2026-02-03T18:16:14.963
Modified: 2026-02-04T17:16:08.663
Link: CVE-2025-61506
No data.