CVE-2025-2490 | Dromara ujcms 9.7.5 File Upload WebFileUploadController.java uploadZip/upload cross site scripting (12/13)
A vulnerability has been found in Dromara ujcms 9.7.5 and classified as problematic. This vulnerability affects the function uploadZip/upload of the file /main/java/com/ujcms/cms/ext/web/backendapi/WebFileUploadController.java of the component File Upload. This manipulation causes cross site scripting.
This vulnerability is registered as CVE-2025-2490. Remote exploitation of the attack is possible. Furthermore, an exploit is available.