Home

Description

A low privileged remote attacker can upload a new or overwrite an existing python script by using a path traversal of the target filename in php resulting in a remote code execution.

PUBLISHED Reserved 2025-04-16 | Published 2025-11-18 | Updated 2025-11-18 | Assigner CERTVDE




HIGH: 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-35 Path Traversal: '.../...//'

Product status

Default status
unaffected

0.0.0 (semver) before 2.2.0
affected

Default status
unaffected

0.0.0 (semver) before 2.2.0
affected

Default status
unaffected

0.0.0 (semver) before 2.2.0
affected

Credits

Noam Moshe from Claroty Team82 finder

Tomer Goldschmidt from Claroty Team82 finder

References

certvde.com/de/advisories/VDE-2025-097

cve.org (CVE-2025-41736)

nvd.nist.gov (CVE-2025-41736)

Download JSON