CVE-2025-15262 is an unrestricted file upload vulnerability in BiggiDroid Simple PHP CMS 1.0, specifically within the Site Logo Handler component of the /admin/edit.php file. This allows authenticated remote attackers to upload arbitrary files by manipulating the 'image' argument, leading to high impact on confidentiality, integrity, and availability. With a CVSS score of 7.2 (HIGH) and public exploit code available, this vulnerability poses a significant risk, despite currently showing no active exploitation or community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:biggidroid:simple_php_cms:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.