CVE-2025-52353 – Badaso CMS Arbitrary Code Execution Vulnerability

The following table lists the changes that have been made to the
CVE-2025-52353 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Aug. 26, 2025

    Action Type Old Value New Value
    Added Description An arbitrary code execution vulnerability in Badaso CMS 2.9.11. The Media Manager allows authenticated users to upload files containing embedded PHP code via the file-upload endpoint, bypassing content-type validation. When such a file is accessed via its URL, the server executes the PHP payload, enabling an attacker to run arbitrary system commands and achieve full compromise of the underlying host. This has been demonstrated by embedding a backdoor within a PDF and renaming it with a .php extension.
    Added Reference https://github.com/uasoft-indonesia/badaso
    Added Reference https://medium.com/@pat.sanitjairak/remote-code-execution-in-a-plain-view-0f86f183543d
Share the Post:

Related Posts