PT-2025-23007 · Unknown · Gowabby Hfish

A7Cc

·

Published

2025-05-27

·

Updated

2025-05-27

·

CVE-2025-5247

CVSS v2.0
7.5
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P

Name of the Vulnerable Software and Affected Versions:

Gowabby HFish version 0.1

Description:

A critical issue has been found in Gowabby HFish, affecting the `LoadUrl` function of the file `viewurl.go`. The manipulation of the argument `r` leads to improper authentication. This issue can be exploited remotely.

Recommendations:

For version 0.1, consider disabling the `LoadUrl` function until a patch is available to prevent improper authentication. Restrict access to the `viewurl.go` file to minimize the risk of exploitation. Avoid using the argument `r` in the affected function until the issue is resolved.

Exploit

Fix

RCE

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-5247

Affected Products

Gowabby Hfish