PT-2025-4386 · Atheros · Atheos
Wangyihang
·
Published
2025-01-10
·
Updated
2025-05-15
·
CVE-2025-22152
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Atheos versions prior to v600
Description
Atheos is a self-hosted browser-based cloud IDE. The issue is related to the lack of proper validation of the
$path and $target parameters across multiple components, allowing an attacker to read, modify, or execute arbitrary files on the server. This can be exploited through various attack vectors present in multiple PHP files.Recommendations
For versions prior to v600, update to v600 to fix the issue. As a temporary workaround, consider restricting access to the vulnerable parameters
$path and $target to minimize the risk of exploitation.Exploit
Fix
Path traversal
Unrestricted File Upload
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Atheos