PT-2025-21368 · Atheros · Atheos
Artant00
·
Published
2025-05-15
·
Updated
2025-05-15
·
CVE-2025-47788
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions:
Atheos versions prior to v602
Description:
Atheos is a self-hosted browser-based cloud IDE. The
$target parameter in "/controller.php" was not properly validated, which could allow an attacker to execute arbitrary files on the server via path traversal.Recommendations:
For versions prior to v602, update to v602 to resolve the issue. As a temporary workaround, consider restricting access to the "/controller.php" endpoint to minimize the risk of exploitation. Avoid using the
$target parameter in the affected endpoint until the issue is resolved.Exploit
Fix
Path traversal
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Atheos