IM
IronMonkey Threat Research

CVE-2025-54927 MEDIUM

Published: 2025-08-20 | Last Modified: 2026-04-15 | Status: Deferred

Description

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized access to sensitive files when an authenticated attackers uses a crafted path input that is processed by the system.

Additional Descriptions (1)

CWE-22: Existe una vulnerabilidad de limitación incorrecta de una ruta a un directorio restringido ('Path Traversal') que podría provocar acceso no autorizado a archivos confidenciales cuando un atacante autenticado utiliza una entrada de ruta manipulada que es procesada por el sistema.

CVSS Metrics

Base Score: 4.9 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactNONE
Availability ImpactNONE

Source: [email protected]

Type: Secondary

Exploitability Score: 1.2

Impact Score: 3.6

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-22
Notification
Message here