Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-52353

EPSS 0.26% · P50
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-52353

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
An arbitrary code execution vulnerability in Badaso CMS 2.9.11. The Media Manager allows authenticated users to upload files containing embedded PHP code via the file-upload endpoint, bypassing content-type validation. When such a file is accessed via its URL, the server executes the PHP payload, enabling an attacker to run arbitrary system commands and achieve full compromise of the underlying host. This has been demonstrated by embedding a backdoor within a PDF and renaming it with a .php extension.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Badaso 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Badaso是Uasoft开源的一个开源的 Laravel Vue 无头 CMS。 Badaso 2.9.11版本存在安全漏洞,该漏洞源于Media Manager允许上传含PHP代码的文件,可能导致任意代码执行。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2025-52353

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-52353

登录查看更多情报信息。

Same Patch Batch · n/a · 2025-08-26 · 29 CVEs total

CVE-2025-25736Kapsch TrafficCom RIS-9260 RSU LEO 安全漏洞
CVE-2024-47192Mahara 安全漏洞
CVE-2024-35203Mahara 安全漏洞
CVE-2025-55443Telpo MDM 安全漏洞
CVE-2025-50971AbanteCart 安全漏洞
CVE-2025-50975IPFire 安全漏洞
CVE-2025-50976IPFire 安全漏洞
CVE-2025-52184Helpy.io 安全漏洞
CVE-2025-50974IPFire 安全漏洞
CVE-2025-57425SourceCodester FAQ Management System 安全漏洞
CVE-2025-56432Nagios XI 安全漏洞
CVE-2025-25737Kapsch TrafficCom RIS-9260 RSU LEO和Kapsch TrafficCom RIS-9160 安全漏洞
CVE-2025-25735Kapsch TrafficCom RIS-9260和Kapsch TrafficCom RIS-9160 安全漏洞
CVE-2025-25734Kapsch TrafficCom RIS-9260 RSU LEO和Kapsch TrafficCom RIS-9160 安全漏洞
CVE-2025-50753Mitrastar GPT-2741GNAC-N2 安全漏洞
CVE-2025-25733Kapsch TrafficCom RIS-9160和Kapsch TrafficCom RIS-9260 RSU LEO 安全漏洞
CVE-2025-25732Kapsch TrafficCom RIS-9160和Kapsch TrafficCom RIS-9260 RSU LEO 安全漏洞
CVE-2025-52036NotesCMS 安全漏洞
CVE-2025-52037NotesCMS 安全漏洞
CVE-2025-52035NotesCMS 安全漏洞

Showing top 20 of 29 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2025-52353

No comments yet


Leave a comment