Junglewise Threat Intelligence

CVE-2025-60731: Perfree PerfreeBlog unrestricted file upload in installTheme

CVE-2025-60731 · Severity: high · CVSS 7.6 · Published 2025-10-24

Technologies: Perfreeblog. Vendors: Perfree.

Executive brief

PerfreeBlog, a Java-based content management system used for building websites and blogs, contains a security flaw in its theme installation feature. An attacker with basic user permissions can upload malicious files to the server, potentially leading to a full takeover of the website. This could result in the theft of sensitive data, website defacement, or a complete disruption of services.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in PerfreeBlog v4.0.11 within the 'installTheme' function. The flaw allows an authenticated user with low-level privileges to upload arbitrary files, such as web shells, to the server via the theme installation mechanism. Because the application fails to properly validate file types or extensions during the upload process, an attacker can achieve remote code execution (RCE) on the underlying host. The vulnerability is reachable over the network and does not require user interaction, though it does require valid login credentials.

Affected products

  • Perfree PerfreeBlog 4.0.11

Timeline

  • 2025-10-24: advisory: Initial disclosure of CVE-2025-60731

References

Related threats