PT-2025-49264 · Unknown · Warehouse Management System

Published

2025-12-05

·

Updated

2025-12-12

·

CVE-2025-65878

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions warehouse management system version 1.2
Description The software has an arbitrary file read issue. The /file/showImageByPath API endpoint does not properly sanitize user-supplied path parameters, potentially allowing an attacker to use directory traversal to access arbitrary files on the server. This could result in the disclosure of sensitive system information. The vulnerable parameter is the file path provided to the /file/showImageByPath endpoint.
Recommendations Apply sanitization to the file path parameter in the /file/showImageByPath endpoint to prevent directory traversal.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-65878

Affected Products

Warehouse Management System