CVE-2025-0225
A vulnerability classified as problematic was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this vulnerability is an unknown functionality of the file /setting/ClassFy/exampleDownload.html. The manipulation of the argument name leads to path traversal: '/../filedir'. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.47%
- CWE
- CWE-25, CWE-23
- Published
- 2025-01-05
- Last modified
- 2026-03-13
Affected products
- Tsinghua Unigroup Electronic Archives System
Weakness type
Related vulnerabilities
- CVE-2026-68959 — SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
- CVE-2026-23877 — Directory Traversal & Filesystem can be accessed by a non-admin user
- CVE-2025-68916 — Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory...
- CVE-2025-58286 — Denial of service (DoS) vulnerability in the office service. Successful exploitation of this...
- CVE-2023-6947 — Best WordPress Gallery Plugin – FooGallery <= 2.4.16 - Authenticated (Contributor+) Directory Traversal
- CVE-2024-2442 — Path Traversal vulnerability in Franklin Fueling System EVO 550/5000
- CVE-2023-52138 — Path traversal via crafted cpio archives in Engrampa archivers
- CVE-2023-6919 — Path Traversal in VGuard IP Camera Network Recorder