CVE-2025-10438
Path Traversal: 'dir/../../filename' vulnerability in Yordam Information Technology Consulting Education and Electrical Systems Industry Trade Inc. Yordam Katalog allows Path Traversal.This issue affects Yordam Katalog: before 21.7.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- EPSS probability
- 0.45%
- CWE
- CWE-27
- Published
- 2025-09-25
- Last modified
- 2026-06-05
Affected products
- Yordam Information Technology Consulting Education and Electrical Systems Industry Trade Inc. Yordam Katalog
Weakness type
Related vulnerabilities
- CVE-2026-76344 — Path Traversal through the Search Dispatch REST API in Splunk Enterprise
- CVE-2026-62391 — Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliases
- CVE-2026-24457 — An unsafe parsing of OpenMQ's configuration, allows a remote attacker to read arbitrary files from...
- CVE-2026-20018 — Cisco Firepower Management Center Software and Firepower Threat Defense Path Traversal Vulnerability
- CVE-2025-66518 — Apache Kyuubi: Unauthorized directory access due to missing path normalization
- CVE-2025-58292 — Denial of service (DoS) vulnerability in the office service. Successful exploitation of this...
- CVE-2025-58761 — Tautulli vulnerable to Unauthenticated Path Traversal in `real_pms_image_proxy`
- CVE-2024-43658 — Using the <redacted> action or <redacted>.sh script, arbitrary files and directories can be deleted using directory traversal.