PT-2025-38528 · Four Faith · Four-Faith Water Conservancy Informatization Platform

Abc_123456

·

Published

2025-09-19

·

Updated

2025-09-19

·

CVE-2025-10709

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Four-Faith Water Conservancy Informatization Platform version 1.0
Description A path traversal vulnerability exists due to the manipulation of the fileName argument. This issue affects some unknown functionality within the files /history/historyDownload.do, /otheruserLogin.do, and /getfile. The vulnerability can be exploited remotely. The exploit is publicly available. The vendor was contacted regarding this disclosure but did not respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-10709

Affected Products

Four-Faith Water Conservancy Informatization Platform