CVE-2023-25402

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
03/03/2023
Last modified:
06/03/2025

Description

CleverStupidDog yf-exam 1.8.0 is vulnerable to File Upload. There is no restriction on the suffix of the uploaded file, resulting in any file upload.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:yf-exam_project:yf-exam:1.8.0:*:*:*:*:*:*:*