PT-2025-30496 · Viewvc · Viewvc
Msanft
·
Published
2025-07-22
·
Updated
2025-07-23
·
CVE-2025-54141
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ViewVC versions 1.1.0 through 1.1.31
ViewVC versions 1.2.0 through 1.2.3
Description
ViewVC is a browser interface for CVS and Subversion version control repositories. The
standalone.py script within the ViewVC distribution can expose the contents of the host server's filesystem through a directory traversal attack.Recommendations
Update to ViewVC version 1.1.31 or later.
Update to ViewVC version 1.2.4 or later.
Exploit
Fix
Path traversal
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Viewvc