PT-2025-49264 · Unknown · Warehouse Management System
Published
2025-12-05
·
Updated
2025-12-12
·
CVE-2025-65878
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
warehouse management system version 1.2
Description
The software has an arbitrary file read issue. The
/file/showImageByPath API endpoint does not properly sanitize user-supplied path parameters, potentially allowing an attacker to use directory traversal to access arbitrary files on the server. This could result in the disclosure of sensitive system information. The vulnerable parameter is the file path provided to the /file/showImageByPath endpoint.Recommendations
Apply sanitization to the file path parameter in the
/file/showImageByPath endpoint to prevent directory traversal.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Warehouse Management System