CVE-2025-65783
Critical · CVSS 9.8Hubert Imoveis e Administracao Ltda Hub v2.0 — Arbitrary File Upload leading to Remote Code Execution (CWE-434)
- CVSS
- 9.8
- nvd
- EPSS
- 0.46%
- 37th pct
- KEV
- No
- Class
- other
- CWE-434
Description
An arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.
Search profile — drives PoC discovery
Symbols /utils/uploadFileuploadFileHub v2.0crafted PDF file upload
Keywords CVE-2025-65783Hubert Imoveis Hubarbitrary file uploaduploadFile RCEHub v2.0 1.27.3PDF file upload exploitcarlos-artmann vulnerability-research
Versions: 1.27.3
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T06:30:39.000Z