Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-55746

Опубликовано: 20 авг. 2025
Источник: nvd
CVSS3: 9.3
CVSS3: 7.5
EPSS Низкий

Описание

Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an unauthenticated actor to modify existing files with arbitrary contents (without changes being applied to the files' database-resident metadata) and / or upload new files, with arbitrary content and extensions, which won't show up in the Directus UI. This vulnerability is fixed in 11.9.3.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:monospace:directus:*:*:*:*:*:node.js:*:*
Версия от 10.8.0 (включая) до 11.9.3 (исключая)

EPSS

Процентиль: 20%
0.00065
Низкий

9.3 Critical

CVSS3

7.5 High

CVSS3

Дефекты

CWE-73

Связанные уязвимости

CVSS3: 9.3
github
6 месяцев назад

Directus allows unauthenticated file upload and file modification due to lacking input sanitization

EPSS

Процентиль: 20%
0.00065
Низкий

9.3 Critical

CVSS3

7.5 High

CVSS3

Дефекты

CWE-73