CVE-2025-9400 | YiFang CMS up to 2.0.5 P_file.php mergeMultipartUpload File unrestricted upload (EUVD-2025-25653)
A vulnerability was found in YiFang CMS up to 2.0.5. It has been classified as critical. This affects the function mergeMultipartUpload of the file app/utils/base/plugin/P_file.php. This manipulation of the argument File causes unrestricted upload.
This vulnerability is registered as CVE-2025-9400. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.