PT-2025-13682 · Unknown · E-Solutions E-Management
Published
2025-03-31
·
Updated
2025-03-31
·
CVE-2025-3021
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
e-solutions e-management (affected versions not specified)
Description
The issue allows an attacker to access confidential files outside the expected scope via the
file parameter in the "/downloadReport.php" endpoint. This could potentially lead to unauthorized access to sensitive information.Recommendations
As a temporary workaround, consider restricting access to the "/downloadReport.php" endpoint until a patch is available.
Avoid using the
file parameter in the affected endpoint until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
E-Solutions E-Management