PT-2025-17712 · Unknown · Database Toolset

Youcef Hamdani

·

Published

2025-04-24

·

Updated

2025-04-29

·

CVE-2025-3065

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Database Toolset plugin versions 1.8.4 and earlier
Description The issue is related to insufficient file path validation in a function, allowing unauthenticated attackers to delete arbitrary files on the server. This can lead to remote code execution when the right file is deleted, such as wp-config.php.
Recommendations For versions 1.8.4 and earlier, update to version 1.8.5 to patch this critical issue. As a temporary workaround, consider restricting access to sensitive files on the server to minimize the risk of exploitation.

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-3065

Affected Products

Database Toolset