Intelligence View
⚡ tsecurity.de Intelligence
CVE-2025-9415 | GreenCMS up to 2.3.0603 index.php?m=admin&c=media&a=fileconnect upload[] unrestricted upload
A vulnerability classified as critical has been found in GreenCMS up to 2.3.0603. This affects an unknown part of the file…
A vulnerability classified as critical has been found in GreenCMS up to 2.3.0603. This affects an unknown part of the file /index.php?m=admin&c=media&a=fileconnect. The manipulation of the argument upload[] leads to unrestricted upload. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is uniquely identified as CVE-2025-9415. The attack is possible to be carried out remotely. Moreover, an exploit is present.
This vulnerability is uniquely identified as CVE-2025-9415. The attack is possible to be carried out remotely. Moreover, an exploit is present.
2. Cyber Threat Intelligence & Forensik
IoC Intelligence (1 Indikatoren)
CVE-2025-9415
Exploit & Remediation Lifecycle Timeline
CVE-2025-9415Entdeckung & Meldung
Schwachstelle identifiziert & registriert
Sicherheits-Advisory
Offizielle Warnung & CVE-Zuweisung
Exploit / PoC
Öffentlicher Nachweis/Code verfügbar (Exploit-DB/EUVD)
In-the-Wild Ausnutzung
Keine Massenausnutzung gemeldet
Patch & Schutzmaßnahmen
Noch kein offizieller Patch dokumentiert
Exploit Weaponization & Public PoC Radar
HIGH EXPLOITABLE · Index 50/100Exploit-DB
Kein EDB-EintragInteraktion
0-ClickAuthentifizierung
Erforderlich3. Compliance, SLA & Vendor Adherence
CISA-SSVC-Triage (vulnrichment)CVE-2025-9415
Exploitation: poc (PoC verfügbar)Automatable: no (Nicht automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2025-08-25T19:49:42.647675Z · CISA Coordinator
Advisory Radar
In herstellerseitiger Prüfung
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Web Referencevuldb.com
-
Web Referencevuldb.com
-
Web Referencevuldb.com
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com