upload of the file /admin#themes of the component Add Theme Handler. The manipulation leads to deserialization.The identification of this vulnerability is CVE-2025-1113. The attack may be initiated remotely. Furthermore, there is an exploit available.