CVE-2025-34100P2CRITICALCVSS 9.3PoCv3.5.02025-07-10
CVE-2025-34100 [CRITICAL] CWE-20 CVE-2025-34100: An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the e
An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file manager and its use of the jQuery File Upload plugin. The plugin fails to properly validate or restrict file types or locations during upload operations, allowing an attacker to upload a malicious .php file and subsequently execute a
nvd