PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-15423 EmpireSoft CVE debrief

A vulnerability was found in EmpireSoft EmpireCMS up to 8.0, impacting the CheckSaveTranFiletype function in e/class/connect.php, allowing unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Defenders should assess the vulnerability's impact on EmpireCMS installations and prioritize verification of versions and file upload restrictions.

Vendor
EmpireSoft
Product
EmpireCMS
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-02
Original CVE updated
2026-10-01
Advisory published
2026-01-02
Advisory updated
2026-10-01

Who should care

Defenders responsible for EmpireCMS installations should assess exposure and prioritize verification of versions and file upload restrictions. This includes reviewing the current version of EmpireCMS in use, understanding the potential impact of unrestricted file uploads, and taking steps to mitigate the vulnerability. Security teams and vulnerability management teams should also be aware of this vulnerability and its potential impact on their environments

Why it matters

Defenders should prioritize verifying EmpireCMS versions and restricting file uploads to prevent potential exploitation of the unrestricted upload vulnerability.

  • Verify EmpireCMS versions to determine exposure
  • Restrict file uploads to prevent potential exploitation
  • Implement input validation and sanitization to prevent similar vulnerabilities
  • Monitor for suspicious file upload activity to detect potential attacks

Technical summary

The vulnerability affects EmpireSoft EmpireCMS up to version 8.0, specifically the CheckSaveTranFiletype function in e/class/connect.php. This allows for unrestricted upload, potentially leading to remote attacks. The vulnerability's impact is considered low, with a CVSS score of 2.1. Defenders should prioritize verifying EmpireCMS versions and restricting file uploads to prevent potential exploitation of the unrestricted upload vulnerability. Implementing input validation and sanitization can also help prevent similar vulnerabilities.

Defensive priority

Defenders should prioritize verifying EmpireCMS versions and restricting file uploads.

Recommended defensive actions

  • Verify EmpireCMS versions and restrict file uploads
  • Implement input validation and sanitization
  • Monitor for suspicious file upload activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD vulnerability detail page provide information on the vulnerability, including its description, CVSS score, and affected versions. The information available indicates that EmpireSoft EmpireCMS versions up to 8.0 are affected by this vulnerability. However, specific details about the number of affected deployments or the extent of potential exposure are not provided. Defenders should verify EmpireCMS versions in their environments and assess the risk of unrestricted file uploads.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-15423 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-15423

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-15423 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15423

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.