CVE-2025-40678

Unrestricted upload vulnerability for dangerous file types on Summar Softwares Portal del Empleado. This vulnerability allows an attacker to upload a dangerous file type by sending a POST request using the parameter cctl00$ContentPlaceHolder1$fuAdjunto in /MemberPages/ntf_absentismo.aspx.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
UNKNOWN
---
INCIBECNA
---
---
CISA-ADPADP
---
---