PT-2025-47547 · Unknown · Dreampie Resty
Sh7Err
·
Published
2025-11-20
·
Updated
2025-11-24
·
CVE-2025-13435
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dreampie Resty versions up to 1.3.1.SNAPSHOT
Description
A security issue exists in Dreampie Resty. Manipulation of the
filename argument within the Request function, located in the file /resty-httpclient/src/main/java/cn/dreampie/client/HttpClient.java of the HttpClient Module, can lead to a path traversal condition. This issue is considered highly complex to exploit, but the exploit has been publicly disclosed. The vendor was notified but did not respond.Recommendations
Versions prior to 1.3.1.SNAPSHOT should be used. As a temporary workaround, consider restricting access to the
Request function until a patch is available.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dreampie Resty