PT-2025-32216 · Unknown · Vedo Suite

Davide Reggiani

+2

·

Published

2025-08-06

·

Updated

2025-10-09

·

CVE-2025-51052

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Vedo Suite version 2024.17
Description A path traversal issue exists in Vedo Suite 2024.17 that may allow remote authenticated attackers to read arbitrary filesystem files. The issue is due to an unsanitized file get contents() function call within the /api vedo/template API endpoint.
Recommendations As a temporary workaround, consider restricting access to the /api vedo/template API endpoint until a fix is available.

Exploit

Fix

Relative Path Traversal

Weakness Enumeration

Related Identifiers

CVE-2025-51052

Affected Products

Vedo Suite