HuoCMS V3.5.1 has a File Upload Vulnerability. An attacker can exploit this flaw to bypass whitelist restrictions and craft malicious files with specific suffixes, thereby gaining control of the server.
No PoCs from references.
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/yggcwhat/CVE-2025-46080