Junglewise Threat Intelligence

CVE-2025-51056: Bottinelli Vedo Suite unrestricted file upload in uploadPreviews

CVE-2025-51056 · Severity: high · CVSS 8.2 · Published 2025-08-06

Technologies: Vedo Suite Project Vedo Suite. Vendors: Vedo Suite Project.

Executive brief

Vedo Suite, a software solution used in textile and fashion design, contains a security flaw in its file handling system. An attacker can upload malicious files to the server, potentially allowing them to take full control of the system or disrupt business operations. This could lead to the theft of proprietary designs or a total service outage.

Technical details

An unrestricted file upload vulnerability exists in Vedo Suite version 2024.17 within the 'uploadPreviews()' custom function located at the '/api_vedo/colorways_preview' endpoint. The application fails to properly validate file types or destination paths, allowing an authenticated attacker to perform path traversal and write files to arbitrary locations on the server's filesystem. By uploading a malicious script (such as a web shell) to a web-accessible directory, the attacker can achieve remote code execution (RCE). While the CVSS vector suggests some user interaction may be involved, the primary mechanism is the exploitation of insecure file upload logic.

Affected products

  • Bottinelli Vedo Suite 2024.17

Timeline

  • 2025-08-06: advisory: Initial disclosure of CVE-2025-51056
  • 2025-08-06: disclosed

References

Related threats