SMG Software Information Portal Unrestricted File Upload Vulnerability Allowing Code Injection and Web Shell Upload

Vulnerability

A vulnerability in SMG Software Information Portal prior to 13.06.2025 allows unrestricted file uploads of dangerous types. This flaw can be exploited for OS command injection, leading to code injection, web shell uploads to the web server, and code inclusion.

Impact

Exploitation of this vulnerability could result in unauthorized code execution on the server via a uploaded web shell.

Remediation

Users are advised to upgrade to versions released on or after 13.06.2025.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
7.4
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.