PT-2025-9134 · Pwndoc · Pwndoc
Jorianwoltjer
·
Published
2025-02-28
·
Updated
2025-04-15
·
CVE-2025-27410
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
PwnDoc versions prior to 1.2.0
Description
The issue concerns the backup restore functionality, which is vulnerable to path traversal in the TAR entry's name. This allows an attacker to overwrite any file on the system with their content, potentially leading to Remote Code Execution as an administrator. The vulnerability can be exploited by overwriting an included
.js file and restarting the container. It affects users with the backups:create and backups:update permissions, which by default are only administrators.Recommendations
For versions prior to 1.2.0, update to version 1.2.0 to resolve the issue. As a temporary workaround, consider restricting the
backups:create and backups:update permissions to prevent potential exploitation. Additionally, avoid using the backup restore functionality until the update is applied.Exploit
Fix
RCE
Path traversal
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pwndoc