630
VMScore

CVE-2025-1336

CVSSv4: 5.3 | CVSSv3: 8.1 | CVSSv2: 4 | VMScore: 630 | EPSS: 0.00039 | KEV: Not Included
Published: 16/02/2025 Updated: 28/02/2025

Vulnerability Summary

Path Traversal Vulnerability in CmsEasy 7.7.7.9 via deleteimg_action Function

A path traversal vulnerability exists in CmsEasy version 7.7.7.9 within the deleteimg_action function of the lib/admin/image_admin.php library. The vulnerability allows remote attackers to manipulate the imgname argument, potentially enabling unauthorized file system access. This security issue has been publicly disclosed, and there is a possibility that the exploit could be used. Despite early notification, the vendor did not provide any response to address the vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

* cmseasy

cmseasy cmseasy 7.7.7.9