PT-2025-18027 · Unknown · Quick Agent V2+1
Masahiro Murashima
+3
·
Published
2025-04-27
·
Updated
2025-04-28
·
CVE-2025-27937
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Quick Agent V3 and Quick Agent V2 (affected versions not specified)
Description
The issue involves an improper limitation of a pathname to a restricted directory, commonly referred to as a Path Traversal issue. If exploited, an arbitrary file in the affected product may be obtained by a remote attacker who can log in to the product. This could allow an attacker to access arbitrary files on the system, potentially leading to unauthorized data access, modification, or even execution of malicious code.
Recommendations
For Quick Agent V3 and Quick Agent V2, validate and sanitize any user input that could be used to manipulate file paths to prevent exploitation of the Path Traversal issue.
As a temporary workaround, consider restricting access to sensitive files and directories until a proper fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quick Agent V2
Quick Agent V3