Vulnerability Database

311,448

Total vulnerabilities in the database

CVE-2025-3125

An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAppUploader admin service endpoint. An authenticated attacker with appropriate privileges can upload a malicious file to a user-controlled location on the server, potentially leading to remote code execution (RCE).

This functionality is restricted by default to admin users; therefore, successful exploitation requires valid credentials with administrative permissions.

  • Published: Nov 5, 2025
  • Updated: Nov 6, 2025
  • CVE: CVE-2025-3125
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 6.7
  • AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L

CWEs: