CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-11630: docsys through 2.02.36 (inclusive); +1 more affected products

CVE-2025-11630. CVSS 3.1 base score 9.8 (CRITICAL, NVD). EPSS 0.00718 (percentile 0.52302), scored 2026-10-06.

Affected technology

docsys · through 2.02.36 (inclusive)
docsys project

DocSys · 2.02.0, 2.02.1, 2.02.2, 2.02.3, 2.02.4, 2.02.5, 2.02.6, 2.02.7, 2.02.8, 2.02.9, 2.02.10, 2.02.11, 2.02.12, 2.02.13, 2.02.14, 2.02.15, 2.02.16, 2.02.17, 2.02.18, 2.02.19, 2.02.20, 2.02.21, 2.02.22, 2.02.23, 2.02.24, 2.02.25, 2.02.26, 2.02.27, 2.02.28, 2.02.29, 2.02.30, 2.02.31, 2.02.32, 2.02.33, 2.02.34, 2.02.35, 2.02.36
RainyGao

Description’s affected range: up to 2.02.36

Component: File Upload
Function: updateRealDoc
File: /Doc/uploadDoc.do

Attack conditions (VulDB, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

VulDB’s CVSS 4.0 assessment (base score 2.1/10) rates confidentiality, integrity and availability impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

Published

CWE
CWE-22
CCR priority
39.4 /100 (P4)
CVSS 3.1
9.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · NVD
EPSS
0.00718 · percentile 0.52404 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-11630.html