CVE-2025-9099 | Acrel Environmental Monitoring Cloud Platform up to 20250804 UploadNewsImg File unrestricted upload
A vulnerability, which was classified as critical, was found in Acrel Environmental Monitoring Cloud Platform up to 20250804. Affected by this issue is some unknown functionality of the file /NewsManage/UploadNewsImg. Such manipulation of the argument File leads to unrestricted upload.
This vulnerability is referenced as CVE-2025-9099. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.