PT-2025-39672 · Unknown · Data Decision Making System
Nu11
·
Published
2025-09-26
·
Updated
2025-09-26
·
CVE-2025-11034
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Dibo Data Decision Making System versions prior to 2.7.0
Description
A path traversal issue exists in Dibo Data Decision Making System. The issue is related to the manipulation of the
filePath argument within the downloadImpTemplet() function located in the /common/dep/common dep.action.jsp file. This allows for remote exploitation. The exploit has been publicly disclosed.Recommendations
Update Dibo Data Decision Making System to a version later than 2.7.0.
As a temporary workaround, restrict access to the
/common/dep/common dep.action.jsp file.
Avoid using the filePath parameter in the downloadImpTemplet() function until the issue is resolved.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Data Decision Making System