CVE-2025-2917

A vulnerability, which was classified as problematic, was found in ChestnutCMS up to 1.5.3. Affected is the function readFile of the file /dev-api/cms/file/read. The manipulation of the argument filePath leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Configurations

Configuration 1 (hide)

cpe:2.3:a:1000cms:chestnutcms:*:*:*:*:*:*:*:*

History

14 Apr 2025, 13:53

Type Values Removed Values Added
First Time 1000cms chestnutcms
1000cms
CPE cpe:2.3:a:1000cms:chestnutcms:*:*:*:*:*:*:*:*
References () https://r0ot.notion.site/ChestnutCMS-1-5-3-Arbitrary-file-read-vulnerability-1ae27d744f7f8074a169ca849e8a1d31?pvs=4 - () https://r0ot.notion.site/ChestnutCMS-1-5-3-Arbitrary-file-read-vulnerability-1ae27d744f7f8074a169ca849e8a1d31?pvs=4 - Broken Link
References () https://vuldb.com/?ctiid.301890 - () https://vuldb.com/?ctiid.301890 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.301890 - () https://vuldb.com/?id.301890 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.520933 - () https://vuldb.com/?submit.520933 - Third Party Advisory, VDB Entry
References () https://r0ot.notion.site/ChestnutCMS-1-5-3-Arbitrary-file-read-vulnerability-1ae27d744f7f8074a169ca849e8a1d31 - () https://r0ot.notion.site/ChestnutCMS-1-5-3-Arbitrary-file-read-vulnerability-1ae27d744f7f8074a169ca849e8a1d31 - Broken Link

01 Apr 2025, 20:26

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad clasificada como problemática en ChestnutCMS hasta la versión 1.5.3. La función readFile del archivo /dev-api/cms/file/read está afectada. La manipulación del argumento filePath provoca un path traversal. Es posible ejecutar el ataque de forma remota. Se ha hecho público el exploit y puede que sea utilizado.

28 Mar 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-28 18:15

Updated : 2025-04-14 13:53


NVD link : CVE-2025-2917

Mitre link : CVE-2025-2917

CVE.ORG link : CVE-2025-2917


JSON object : View

Products Affected

1000cms

  • chestnutcms
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')