Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-11842

Опубликовано: 16 окт. 2025
Источник: nvd
CVSS3: 6.3
CVSS2: 6.5
EPSS Низкий

Описание

A security vulnerability has been detected in Shazwazza Smidge up to 4.5.1. The impacted element is an unknown function of the component Bundle Handler. The manipulation of the argument Version leads to path traversal. Remote exploitation of the attack is possible. Upgrading to version 4.6.0 is sufficient to resolve this issue. It is recommended to upgrade the affected component.

EPSS

Процентиль: 25%
0.00087
Низкий

6.3 Medium

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.3
github
4 месяца назад

Smidge is vulnerable to Path Traversal

EPSS

Процентиль: 25%
0.00087
Низкий

6.3 Medium

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-22