CVE-2025-52130 – WebErpMesv2 File Upload RCE

The following table lists the changes that have been made to the
CVE-2025-52130 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Aug. 25, 2025

    Action Type Old Value New Value
    Added Description File upload vulnerability in WebErpMesv2 1.17 in the app/Http/Controllers/FactoryController.php controller. This flaw allows an authenticated attacker to upload arbitrary files, including PHP scripts, which can be accessed via direct GET requests, potentially resulting in remote code execution (RCE) on the web server.
    Added Reference https://github.com/SMEWebify/WebErpMesv2
    Added Reference https://medium.com/@The_Hiker/wrong-variable-name-leads-to-rce-cve-2025-52130-8ff59a7d245c
Share the Post:

Related Posts