CRITICAL🇵🇱 Wersja polska

CVE-2025-65473

CVSS 9.1v3.1pub. 2025-12-11upd. 2025-12-15

An arbitrary file rename vulnerability in the /admin/filer.php component of EasyImages 2.0 v2.8.6 and below allows attackers with Administrator privileges to execute arbitrary code via injecting a crafted payload into an uploaded file name.

🤖 AI Analysis
How it works

The /admin/filer.php component allows renaming of uploaded files without proper input data validation (CWE-73: External Control of File Name or Path). An attacker injects a crafted payload into the uploaded file name during the rename operation. This results in the file receiving a name that allows it to be interpreted and executed by the server as executable code.

Impact

An attacker can execute arbitrary code on the server (RCE), which consequently leads to full system takeover, disclosure of confidential data, integrity violation, and service availability disruption.

Mitigation & patch

Security patches available from the vendor should be applied according to the references. Until the update is performed, it is recommended to restrict access to the administration panel (/admin/filer.php) exclusively to trusted IP addresses and increase monitoring of administrative activity.

Who is affected

EasyImages 2.0 in version 2.8.6 and earlier (Easyimages2.0 Project).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Easyimages2.0 Project Easyimages2.0

    APP
    Easyimages2.0 Project
    ≤ 2.8.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2025-65474CRITICAL9.8PL ✓same product

EasyImages 2.0 – RCE przez dowolne przemianowanie pliku w panelu admina

CVE-2025-65471HIGH8.8same product

An arbitrary file upload vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below ...

CVE-2025-65472HIGH8.8same product

A Cross-Site Request Forgery (CSRF) in the /admin/admin.inc.php component of EasyImages 2.0 v2.8.6 and below a...

CVE-2025-13415MEDIUM5.1same product

A vulnerability was identified in icret EasyImages up to 2.8.6. This affects an unknown part of the file /app/...

CVE-2023-33599MEDIUM6.1same product

EasyImages2.0 ≤ 2.8.1 is vulnerable to Cross Site Scripting (XSS) via viewlog.php.