{"id":"CVE-2025-65783","title":"An arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.","summary":"An arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-434"],"vendor":"hubert","product":"hub","affected":["hub = 2.0.1.27.3"],"published":"2026-01-13","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-65783","references":[{"url":"https://github.com/carlos-artmann/vulnerability-research/tree/main/CVE-2025-65783","label":"cve@mitre.org"}],"tags":["nvd"],"epss":0.00516,"epssPercentile":0.42775,"ingestedAt":"2026-07-06T16:44:34.508Z","slug":"CVE-2025-65783","body":"## Overview\n\nAn arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.\n\n## Affected\n\n- `hub = 2.0.1.27.3`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}