CVE-2025-52207: Miko Mikopbx
Critical severity, CVSS 9.9. EPSS: 1.6% chance of exploitation in the next 30 days.
PBXCoreREST/Controllers/Files/PostController.php in MikoPBX through 2024.1.114 allows uploading a PHP script to an arbitrary directory.
Affected products
- Miko Mikopbx: up to and including 2024.1.114
Published 2025-06-27. Last modified 2026-06-17.