5.3
CVSSv4

CVE-2025-1336

CVSSv4: 5.3 | CVSSv3: 4.3 | CVSSv2: 4 | VMScore: 630 | EPSS: 0.00039 | KEV: Not Included
Published: 16/02/2025 Updated: 16/02/2025

Vulnerability Summary

Path Traversal Vulnerability in CmsEasy 7.7.7.9 via deleteimg_action Function

A path traversal vulnerability exists in CmsEasy version 7.7.7.9 within the deleteimg_action function of the lib/admin/image_admin.php library. The vulnerability allows remote attackers to manipulate the imgname argument, potentially enabling unauthorized file system access. This security issue has been publicly disclosed, and there is a possibility that the exploit could be used. Despite early notification, the vendor did not provide any response to address the vulnerability.