PT-2025-35218 · Yeqifu · Yeqifu Carrental

Coiledmag4

·

Published

2025-08-29

·

Updated

2025-08-29

·

CVE-2025-9650

CVSS v2.0
5.5
VectorAV:N/AC:L/Au:S/C:N/I:P/A:P

Name of the Vulnerable Software and Affected Versions:

yeqifu carRental versions prior to 3fabb7eae93d209426638863980301d6f99866b3

Description:

A path traversal issue exists in the `removeFileByPath` function within the `src/main/java/com/yeqifu/sys/utils/AppFileUtils.java` file. The manipulation of the `carimg` argument allows for path traversal, and the issue is remotely exploitable. The exploit has been publicly disclosed.

Recommendations:

Update yeqifu carRental to a version prior to 3fabb7eae93d209426638863980301d6f99866b3.

As a temporary workaround, consider restricting access to the `removeFileByPath` function until a patch is available.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-9650

Affected Products

Yeqifu Carrental