A Path traversal vulnerability in the file
download functionality was identified. This vulnerability allows
unauthenticated users to download arbitrary files, in the context of the
application server, from the Linux server.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.cirosec.de/sa/sa-2025-003 |
![]() ![]() |
History
Fri, 16 May 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 16 May 2025 12:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A Path traversal vulnerability in the file download functionality was identified. This vulnerability allows unauthenticated users to download arbitrary files, in the context of the application server, from the Linux server. | |
Title | Local file inclusion vulnerability in LIVE CONTRACT | |
Weaknesses | CWE-20 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: cirosec
Published: 2025-05-16T12:09:41.347Z
Updated: 2025-05-16T13:04:26.030Z
Reserved: 2025-03-14T12:24:17.830Z
Link: CVE-2025-2305

Updated: 2025-05-16T13:04:22.444Z

Status : Awaiting Analysis
Published: 2025-05-16T13:15:52.063
Modified: 2025-05-16T14:42:18.700
Link: CVE-2025-2305

No data.