PT-2025-14038 · Unknown · Include Url

Timomangcut

·

Published

2025-04-01

·

Updated

2025-04-01

·

CVE-2025-30594

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions NotFound Include URL versions 0.3.5 and earlier
Description The issue is related to an Improper Limitation of a Pathname to a Restricted Directory, also known as a Path Traversal vulnerability. This vulnerability affects the Include URL feature, allowing unauthorized access to files outside the intended directory.
Recommendations For versions 0.3.5 and earlier, consider restricting access to the Include URL feature until a patch is available. As a temporary workaround, limit the paths that can be accessed through the Include URL to prevent traversal outside the restricted directory.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-30594

Affected Products

Include Url