CVE-2025-2705 | Digiwin ERP 5.1 /Api/FileUploadApi.ashx DoUpload/DoWebUpload File unrestricted upload
A vulnerability classified as critical has been found in Digiwin ERP 5.1. Affected is the function DoUpload/DoWebUpload of the file /Api/FileUploadApi.ashx. The manipulation of the argument File leads to unrestricted upload.
This vulnerability is traded as CVE-2025-2705. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.