CNNVD-202507-3164 Information

CNNVD ID

CNNVD-202507-3164

CVE-2025-8128

  • CNNVD Published: 2025-07-25

Description (Chinese)

letao是ShuGang Zhou个人开发者的一个鞋子商城。 letao 存在代码问题漏洞,该漏洞源于对文件routesfproduct.js中参数pictrdtz的错误操作导致无限制上传。

Description (English)

Letao is a shoe mall for ShuGang Zhou personal developers. Letao has a code problem loophole, which results from an error in the pictrdtz parameter in the file routesfproject.js, resulting in unlimited upload.

Hazard Level

High

Vulnerability Type

代码问题

Affected Vendor

个人开发者

Published

2025-07-25

Last Modified

2026-02-24

References

https://github.com/zhousg/letao/issues/13 https://github.com/zhousg/letao/issues/13#issue-2977017027 https://vuldb.com/?ctiid.317513 https://vuldb.com/?id.317513 https://vuldb.com/?submit.619740 https://access.redhat.com/security/cve/cve-2025-8128

Share on: