Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-41723

Опубликовано: 22 окт. 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

The importFile SOAP method is vulnerable to a directory traversal attack. An unauthenticated remote attacker bypass the path restriction and upload files to arbitrary locations.

EPSS

Процентиль: 70%
0.00635
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-35

Связанные уязвимости

CVSS3: 9.8
github
4 месяца назад

The importFile SOAP method is vulnerable to a directory traversal attack. An unauthenticated remote attacker bypass the path restriction and upload files to arbitrary locations.

EPSS

Процентиль: 70%
0.00635
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-35