Metrics
Affected Vendors & Products
Mon, 01 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mogublog Project
Mogublog Project mogublog |
|
| Vendors & Products |
Mogublog Project
Mogublog Project mogublog |
Mon, 01 Dec 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Dec 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in moxi159753 Mogu Blog v2 up to 5.2. The impacted element is the function FileOperation.unzip of the file /networkDisk/unzipFile of the component ZIP File Handler. Such manipulation of the argument fileUrl leads to path traversal. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | moxi159753 Mogu Blog v2 ZIP File unzipFile FileOperation.unzip path traversal | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-12-01T08:32:05.364Z
Updated: 2025-12-01T14:05:54.284Z
Reserved: 2025-11-30T19:51:30.296Z
Link: CVE-2025-13816
Updated: 2025-12-01T14:05:38.739Z
Status : Awaiting Analysis
Published: 2025-12-01T09:16:05.593
Modified: 2025-12-01T15:39:33.110
Link: CVE-2025-13816
No data.