CVE-2025-5523 | enilu web-flash 1.0 File Upload upload fileService.upload cross site scripting (ICAXTM)
A vulnerability classified as problematic has been found in enilu web-flash 1.0. This affects the function fileService.upload of the file src/main/java/cn/enilu/flash/api/controller/FileController/upload of the component File Upload. The manipulation of the argument File leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-5523. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.VulDB Recent EntriesRead More