Security Advisory

CVE-2025-60268

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-10-10 00:00:00
Last updated 2025-10-10 18:55:13
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An attacker with normal privileges was able to upload a malicious file that would lead to remote code execution.