A weakness has been identified in xuhuisheng lemon up to...
        
  Moderate severity
        
          Unreviewed
      
        Published
          Aug 25, 2025 
          to the GitHub Advisory Database
          •
          Updated Sep 12, 2025 
      
  
Description
        Published by the National Vulnerability Database
      Aug 25, 2025 
    
  
        Published to the GitHub Advisory Database
      Aug 25, 2025 
    
  
        Last updated
      Sep 12, 2025 
    
  
A weakness has been identified in xuhuisheng lemon up to 1.13.0. This affects the function uploadImage of the file CmsArticleController.java of the component com.mossle.cms.web.CmsArticleController.uploadImage. This manipulation of the argument Upload causes unrestricted upload. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.
References