Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jacopoaugelli

#17784of 53,632
15.1Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2025-32216
6.5
2025-08-06
Unknown · Vedo Suite · CVE-2025-51052
**Name of the Vulnerable Software and Affected Versions** Vedo Suite version 2024.17 **Description** A path traversal issue exists in Vedo Suite 2024.17 that may allow remote authenticated attackers to read arbitrary filesystem files. The issue is due to an unsanitized `file get contents()` function call within the `/api vedo/template` API endpoint. **Recommendations** As a temporary workaround, consider restricting access to the `/api vedo/template` API endpoint until a fix is available.
PT-2025-32219
8.6
2025-08-06
Unknown · Vedo Suite · CVE-2025-51055
**Name of the Vulnerable Software and Affected Versions** Vedo Suite version 2024.17 **Description** The application stores credentials in clear-text within the `/api vedo/configuration/config.yml` file. This file contains sensitive information, including credentials, secret keys, and database information. **Recommendations** Ensure the `/api vedo/configuration/config.yml` file is appropriately secured to prevent unauthorized access.