PT-2026-6324 · Navigatum · Navigatum
Gebhartleopold-Coder
·
Published
2026-02-04
·
Updated
2026-02-05
·
CVE-2026-25575
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
NavigaTUM versions prior to commit 86f34c7
Description
NavigaTUM is a website and API used for searching locations. A path traversal flaw exists in the
propose edits API endpoint, allowing unauthenticated users to overwrite files in directories accessible to the application user, such as /cdn. This is achieved by providing unsanitized file keys containing traversal sequences (e.g., ../../) within the JSON payload, enabling attackers to bypass the intended temporary directory and potentially replace public images or exhaust server storage.API Endpoints
/propose editsVulnerable Parameters or Variables
file keys (within the JSON payload)Recommendations
Update NavigaTUM to commit 86f34c7 or later.
Exploit
Fix
Relative Path Traversal
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Navigatum