PT-2025-39293 · Datart · Datart

Xiaoxiaoranxxx

·

Published

2025-09-24

·

Updated

2025-10-10

·

CVE-2025-56815

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Datart version 1.0.0-rc.3
Description The software is susceptible to a Directory Traversal issue through an unrestricted file upload. The server utilizes MultipartFile.transferTo() to save uploaded files to a user-controllable path without sufficient filename validation. This allows for potential manipulation of the file save location. The vulnerable API endpoint is /viz/image using the POST method. The MultipartFile object is used in the process.
Recommendations Apply strict validation to the filename before saving the uploaded file to prevent directory traversal.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-56815

Affected Products

Datart