CNNVD-202511-1781 Information

CNNVD ID

CNNVD-202511-1781

CVE-2025-13198

  • CNNVD Published: 2025-11-15

Description (Chinese)

DouPHP是中国DouPHP公司的一个企业建站系统。 DouPHP 1.8 Release 20251022及之前版本存在代码问题漏洞,该漏洞源于文件upload/include/file.class.php中参数File的错误操作,可能导致无限制上传。

Description (English)

DouPHP is an enterprise construction system of DouPHP in China. There is a code problem loophole in DouPHP 1.8 Releaase 20251022 and earlier versions, which stems from the error of File, the parameter in fileupload/include/file.class.php, which may lead to unlimited uploading.

Hazard Level

High

Vulnerability Type

代码问题

Affected Vendor

DouPHP

Published

2025-11-15

Last Modified

2026-02-24

References

https://github.com/electroN1chahaha/My-CVE/issues/1 https://vuldb.com/?ctiid.332496 https://vuldb.com/?submit.685544 https://vuldb.com/?id.332496 https://access.redhat.com/security/cve/cve-2025-13198

Patch

https://www.douphp.com/download

Share on: