PT-2025-37103 · 299Ko · 299Ko

Yu Bao

·

Published

2025-09-10

·

Updated

2025-09-10

·

CVE-2025-10232

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions: 299ko versions up to 2.0.0
Description: A weakness exists in 299ko due to path traversal in the getSentDir/delete function of the plugin/filemanager/controllers/FileManagerAPIController.php file. This issue is remotely exploitable, and the exploit has been publicly released. The vendor was notified but did not respond.
Recommendations: Versions prior to 2.0.0: As a temporary workaround, consider restricting access to the plugin/filemanager/controllers/FileManagerAPIController.php file to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-10232

Affected Products

299Ko