PT-2025-23271 · Unknown · Airpointer
Published
2025-05-30
·
Updated
2025-05-30
·
CVE-2025-4634
CVSS v3.1
4.1
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
airpointer version 2.4.107-2
Description
The web portal on airpointer presented a local file inclusion issue. A malicious user with administrative privileges in the web portal could manipulate requests to view files on the filesystem.
Recommendations
For airpointer version 2.4.107-2, consider restricting access to the web portal to prevent exploitation until a fix is available. As a temporary workaround, limit administrative privileges to minimize the risk of manipulation. At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Airpointer