{"id":"CVE-2025-9406","summary":"xuhuisheng lemon CmsArticleController.java uploadImage unrestricted upload","details":"A weakness has been identified in xuhuisheng lemon up to 1.13.0. This affects the function uploadImage of the file CmsArticleController.java of the component com.mossle.cms.web.CmsArticleController.uploadImage. This manipulation of the argument Upload causes unrestricted upload. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.","modified":"2026-08-12T03:51:27.398479487Z","published":"2025-08-25T03:32:06.413Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/9xxx/CVE-2025-9406.json","cna_assigner":"VulDB","cwe_ids":["CWE-284","CWE-434"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/9xxx/CVE-2025-9406.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-9406"},{"type":"ADVISORY","url":"https://vuldb.com/?id.321242"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.633593"},{"type":"REPORT","url":"https://github.com/xuhuisheng/lemon/issues/212"},{"type":"REPORT","url":"https://github.com/xuhuisheng/lemon/issues/212#issue-3317490086"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.321242"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/xuhuisheng/lemon","events":[{"introduced":"fd7cdf736873cca042dd1481b1ef5c64e9387507"},{"last_affected":"2bf80b638538ea276fe91c74614befac6d5a8ab2"}],"database_specific":{"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:mossle:lemon:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.0"},{"last_affected":"1.0"},{"introduced":"1.1"},{"last_affected":"1.1"},{"introduced":"1.2"},{"last_affected":"1.2"},{"introduced":"1.3"},{"last_affected":"1.3"},{"introduced":"1.4"},{"last_affected":"1.4"},{"introduced":"1.5"},{"last_affected":"1.5"},{"introduced":"1.6"},{"last_affected":"1.6"},{"introduced":"1.7"},{"last_affected":"1.7"},{"introduced":"1.8"},{"last_affected":"1.8"},{"introduced":"1.9"},{"last_affected":"1.9"},{"introduced":"1.10"},{"last_affected":"1.10"},{"introduced":"1.11"},{"last_affected":"1.11"},{"introduced":"1.12"},{"last_affected":"1.12"},{"introduced":"1.13.0"},{"last_affected":"1.13.0"},{"introduced":"0"}]}}],"versions":["1.0","1.1","1.10","1.11","1.12","1.13.0","1.2","1.3","1.4","1.5","1.6","1.7","1.8","1.9","lemon-1.13.0","lemon-1.12.0","lemon-1.11.0","lemon-1.10.0","lemon-1.9.0","lemon-1.8.0","lemon-1.7.0","lemon-1.6.1","lemon-1.6.0","lemon-1.5.1","lemon-1.5.0","lemon-1.4.0","lemon-1.3.1","lemon-1.3.0","lemon-1.2.0","lemon-1.1.0","lemon-1.0.1","lemon-1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-9406.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}