A Path traversal vulnerability in the file
download functionality was identified. This vulnerability allows
unauthenticated users to download arbitrary files, in the context of the
application server, from the Linux server.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.cirosec.de/sa/sa-2025-003 |
|
History
Fri, 16 May 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 16 May 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Path traversal vulnerability in the file download functionality was identified. This vulnerability allows unauthenticated users to download arbitrary files, in the context of the application server, from the Linux server. | |
| Title | Local file inclusion vulnerability in LIVE CONTRACT | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cirosec
Published: 2025-05-16T12:09:41.347Z
Updated: 2025-05-16T13:04:26.030Z
Reserved: 2025-03-14T12:24:17.830Z
Link: CVE-2025-2305
Updated: 2025-05-16T13:04:22.444Z
Status : Awaiting Analysis
Published: 2025-05-16T13:15:52.063
Modified: 2025-05-16T14:42:18.700
Link: CVE-2025-2305
No data.