Home
HIGH: 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
0.0.0 (semver) before 2.2.0
affected
Default status
unaffected
0.0.0 (semver) before 2.2.0
affected
Default status
unaffected
0.0.0 (semver) before 2.2.0
affected
Description
A low privileged remote attacker can upload a new or overwrite an existing python script by using a path traversal of the target filename in php resulting in a remote code execution.
Problem types
CWE-35 Path Traversal: '.../...//'
Product status
0.0.0 (semver) before 2.2.0
0.0.0 (semver) before 2.2.0
0.0.0 (semver) before 2.2.0
Credits
Noam Moshe from Claroty Team82
Tomer Goldschmidt from Claroty Team82
References
certvde.com/de/advisories/VDE-2025-097