PT-2026-6324 · Navigatum · Navigatum
Gebhartleopold-Coder
·
Publicado
2026-02-04
·
Atualizado
2026-02-05
·
CVE-2026-25575
CVSS v4.0
8.8
Alta
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
NavigaTUM versions prior to commit 86f34c7
Description
NavigaTUM is a website and API used for searching locations. A path traversal flaw exists in the
propose edits API endpoint, allowing unauthenticated users to overwrite files in directories accessible to the application user, such as /cdn. This is achieved by providing unsanitized file keys containing traversal sequences (e.g., ../../) within the JSON payload, enabling attackers to bypass the intended temporary directory and potentially replace public images or exhaust server storage.API Endpoints
/propose editsVulnerable Parameters or Variables
file keys (within the JSON payload)Recommendations
Update NavigaTUM to commit 86f34c7 or later.
Exploit
Correção
Relative Path Traversal
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Navigatum