PT-2025-25519 · Unknown · Spring-Boot-In-Action

Shenxiusecurity

·

Published

2025-06-16

·

Updated

2025-06-16

·

CVE-2025-6108

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions hansonwang99 Spring-Boot-In-Action up to 807fd37643aa774b94fd004cc3adbd29ca17e9aa
Description A critical issue was found in the function watermarkTest of the file /springbt watermark/src/main/java/cn/codesheep/springbt watermark/service/ImageUploadService.java of the component File Upload. The manipulation of the argument filename leads to path traversal. The attack can be launched remotely.
Recommendations As a temporary workaround, consider disabling the watermarkTest function until a fix is available. Restrict access to the File Upload component to minimize the risk of exploitation. Avoid using the filename argument in the affected file until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-6108

Affected Products

Spring-Boot-In-Action