Junglewise Threat Intelligence

CVE-2025-60735: Perfree PerfreeBlog unrestricted file upload in installPlugin

CVE-2025-60735 · Severity: high · CVSS 7.6 · Published 2025-10-24

Technologies: Perfreeblog. Vendors: Perfree.

Executive brief

PerfreeBlog, a Java-based content management system (CMS), contains a security flaw in its plugin installation feature. An attacker with basic user permissions can upload malicious files to the server. This could allow an unauthorized individual to gain control over the website, access sensitive data, or disrupt business operations.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in PerfreeBlog v4.0.11 within the 'installPlugin' function. The application fails to properly validate or sanitize file extensions or content during the plugin installation process. An attacker with low-level authenticated access can exploit this over the network to upload and potentially execute arbitrary code (such as a web shell) on the host server. This can lead to full system compromise, unauthorized data access, or service disruption. As of the advisory date, users should exercise caution with plugin installations and restrict administrative access.

Affected products

  • Perfree PerfreeBlog 4.0.11

Timeline

  • 2025-10-24: disclosed: Initial NVD publication

References

Related threats