CVE-2025-14522
Unknown Unknown - Not Provided

BaseFortify

Vulnerability report for CVE-2025-14522, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2025-12-11

Last updated on: 2026-04-29

Assigner: VulDB

Description

A vulnerability was detected in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. The impacted element is an unknown function of the file /Public/Kindeditor/php/upload_json.php. Performing manipulation of the argument imgFile results in unrestricted upload. It is possible to initiate the attack remotely. The exploit is now public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2025-12-11
Last Modified
2026-04-29
Generated
2026-07-26
AI Q&A
2025-12-11
EPSS Evaluated
2026-07-25
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
baowzh hfly *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in the baowzh hfly software, specifically in an unknown function within the file /Public/Kindeditor/php/upload_json.php. It involves manipulation of the argument 'imgFile' which allows an attacker to perform an unrestricted file upload. This means an attacker can remotely upload files without proper restrictions, potentially leading to unauthorized actions on the system.

Detection Guidance

This vulnerability can be detected by searching for the presence of the vulnerable upload endpoint `/Public/Kindeditor/php/upload_json.php` on your web servers. One suggested method is using Google dorking with the query `inurl:Public/Kindeditor/php/upload_json.php` to identify potentially vulnerable targets. Additionally, monitoring HTTP requests for attempts to manipulate the `imgFile` parameter to upload files can help detect exploitation attempts. Specific commands are not provided, but you can use web server access logs or intrusion detection systems to filter for requests containing `imgFile` uploads to this path. [1]

Impact Analysis

The vulnerability allows remote attackers to upload files without restriction, which can lead to unauthorized access, execution of malicious code, or compromise of the affected system. This can result in data breaches, system downtime, or further exploitation by attackers.

Compliance Impact

The provided resources do not contain information regarding the impact of this vulnerability on compliance with common standards and regulations such as GDPR or HIPAA.

Mitigation Strategies

There are no known mitigations or countermeasures available for this vulnerability. The recommended immediate step is to replace the affected component or product with an alternative that does not contain this vulnerability. Since the vendor has not provided a patch or response, discontinuing use of the vulnerable software is advised to prevent exploitation. [1]

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-14522. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart