PT-2025-46728 · Longjing Technology · Longjing Technology Bems Api
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Longjing Technology BEMS API versions up to and including 1.21
Description
The software contains an unauthenticated arbitrary file download issue in the 'downloads' endpoint. The
fileName parameter lacks proper sanitization, enabling attackers to construct file traversal sequences and gain access to sensitive files outside the designated directory.Recommendations
Apply updates to versions prior to 1.21.
Exploit
Fix
Path traversal
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Longjing Technology Bems Api