Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-51539

Опубликовано: 19 авг. 2025
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

EzGED3 3.5.0 contains an unauthenticated arbitrary file read vulnerability due to improper access control and insufficient input validation in a script exposed via the web interface. A remote attacker can supply a crafted path parameter to a PHP script to read arbitrary files from the filesystem. The script lacks both authentication checks and secure path handling, allowing directory traversal attacks (e.g., ../../../) to access sensitive files such as configuration files, database dumps, source code, and password reset tokens. If phpMyAdmin is exposed, extracted credentials can be used for direct administrative access. In environments without such tools, attacker-controlled file reads still allow full database extraction by targeting raw MySQL data files. The vendor states that the issue is fixed in 3.5.72.27183.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ezged:ezged3:*:*:*:*:*:*:*:*
Версия от 3.5.0 (включая) до 3.5.72.27183 (исключая)

EPSS

Процентиль: 32%
0.00124
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 5.3
github
6 месяцев назад

EzGED3 3.5.0 contains an unauthenticated arbitrary file read vulnerability due to improper access control and insufficient input validation in a script exposed via the web interface. A remote attacker can supply a crafted path parameter to a PHP script to read arbitrary files from the filesystem. The script lacks both authentication checks and secure path handling, allowing directory traversal attacks (e.g., ../../../) to access sensitive files such as configuration files, database dumps, source code, and password reset tokens. If phpMyAdmin is exposed, extracted credentials can be used for direct administrative access. In environments without such tools, attacker-controlled file reads still allow full database extraction by targeting raw MySQL data files. The vendor states that the issue is fixed in 3.5.72.27183.

EPSS

Процентиль: 32%
0.00124
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-284