CVE-2025-45855 – Erupt Elevation of Privilege (Arbitrary Code Execution)

The following table lists the changes that have been made to the
CVE-2025-45855 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jun. 03, 2025

    Action Type Old Value New Value
    Added Description An arbitrary file upload vulnerability in the component /upload/GoodsCategory/image of erupt v1.12.19 allows attackers to execute arbitrary code via uploading a crafted file.
    Added Reference https://gist.github.com/Cafe-Tea/b72d442be434e1dafe7810c938892b06
    Added Reference https://github.com/erupts/erupt
    Added Reference https://www.erupt.xyz/#%21/
Share the Post:

Related Posts