CVE-2025-7895 | harry0703 MoneyPrinterTurbo up to 1.2.6 File Extension video.py upload_bgm_file unrestricted upload (EUVD-2025-22024)
A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6. It has been rated as critical. Affected by this vulnerability is the function upload_bgm_file of the file app/controllers/v1/video.py of the component File Extension Handler. The manipulation of the argument File leads to unrestricted upload.
This vulnerability is traded as CVE-2025-7895. It is possible to initiate the attack remotely. There is no exploit available.