Metrics
Affected Vendors & Products
Tue, 09 Dec 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Verysync
Verysync verysync |
|
| Vendors & Products |
Verysync
Verysync verysync |
Mon, 08 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 07 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in Verysync 微力同步 up to 2.21.3. This impacts an unknown function of the file /rest/f/api/resources/f96956469e7be39d/tmp/text.txt?override=false of the component Web Administration Module. Executing manipulation can lead to unrestricted upload. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Verysync 微力同步 Web Administration text.txt unrestricted upload | |
| Weaknesses | CWE-284 CWE-434 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-12-08T17:12:27.191Z
Reserved: 2025-12-06T17:34:34.823Z
Link: CVE-2025-14199
Updated: 2025-12-08T17:02:59.036Z
Status : Awaiting Analysis
Published: 2025-12-07T17:15:47.487
Modified: 2025-12-08T18:26:49.133
Link: CVE-2025-14199
No data.