CVE-2025-0401
CVE-2025-0401 is a critical path traversal vulnerability found in the 1902756969 reggie 1.0 software. Specifically, the vulnerability lies within the 'download' function of the 'src/main/java/com/itheima/reggie/controller/CommonController.java' file. Attackers can remotely exploit this flaw by manipulating the 'name' argument. Although the CVSS score is 5.3, the SOCRadar Vulnerability Risk Score (SVRS) is 60, indicating a moderate risk with potential for exploitation. Public exploit code is available, increasing the likelihood of attacks being launched in the wild. This vulnerability allows unauthorized access to sensitive files and directories on the server. Immediate patching is recommended to prevent potential data breaches and system compromise. The risk stems from the ability to bypass security measures and access restricted areas.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.