All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2025-69828
CRITICALpublished 2026-01-22 17:16 UTC · 7 months ago · modified 2026-06-17 10:00 UTC
10.0
CVSS / 10
// description
File Upload vulnerability in TMS Global Software TMS Management Console v.6.3.7.27386.20250818 allows a remote attacker to execute arbitrary code via the Logo upload in /Customer/AddEdit
// weaknesses (CWE)
- CWE-434