MikoPBX through 2024.1.114 contains an authenticated unrestricted file upload vulnerability caused by allowing PHP script uploads in PBXCoreREST/Controllers/Files/PostController.php.
id: CVE-2025-52207
info:
name: MikoPBX - Unrestricted File Upload
author: darses
severity: cr
...