Arbitrary file upload in SAP NetWeaver - CVE-2025-31324
Published: April 25, 2025 / Updated: January 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file during file upload in Metadata Uploader within the Visual Composer development server. A remote non-authenticated attacker can upload a malicious file and execute it on the server.
Note, the vulnerability is being actively exploited in the wild.
Affected software
How to mitigate CVE-2025-31324
Links to Public Exploits and PoC-codes
- Exploit #12314 - CVE-2025-31324 (January 16, 2026)
- Exploit #11387 - Onapsis-Mandiant-CVE-2025-31324-Vuln-Compromise-Assessment (May 9, 2025)
- Exploit #11384 - CVE-2025-31324 (May 9, 2025)
- Exploit #11382 - sap_netweaver_cve-2025-31324- (May 9, 2025)
- Exploit #11372 - CVE-2025-31324-File-Upload (May 9, 2025)
- Exploit #11368 - Burp_CVE-2025-31324 (May 9, 2025)
- Exploit #11354 - CVE-2025-31324_PoC_SAP (May 2, 2025)
- Exploit #11353 - Onapsis_CVE-2025-31324_Scanner_Tools (May 2, 2025)
- Exploit #11352 - CVE-2025-31324_PoC (May 2, 2025)
- Exploit #11351 - SAP-CVE-2025-31324 (May 2, 2025)
- Exploit #11346 - ExploitCVE2025 (May 2, 2025)