A vulnerability was found in JeeWMS up to 20250504. It has been declared as critical. This vulnerability affects the function doAdd of the file /cgformTemplateController.do?doAdd. The manipulation leads to path traversal. The attack can be initiated remotely. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
References
Link | Resource |
---|---|
https://gitee.com/erzhongxmu/JEEWMS/issues/IC5FNV | Issue Tracking |
https://vuldb.com/?ctiid.310678 | Permissions Required VDB Entry |
https://vuldb.com/?id.310678 | Third Party Advisory VDB Entry |
Configurations
History
11 Sep 2025, 20:43
Type | Values Removed | Values Added |
---|---|---|
First Time |
Huayi-tec
Huayi-tec jeewms |
|
CPE | cpe:2.3:a:huayi-tec:jeewms:*:*:*:*:*:*:*:* | |
References | () https://gitee.com/erzhongxmu/JEEWMS/issues/IC5FNV - Issue Tracking | |
References | () https://vuldb.com/?ctiid.310678 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.310678 - Third Party Advisory, VDB Entry |
02 Jun 2025, 17:32
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-31 17:15
Updated : 2025-09-11 20:43
NVD link : CVE-2025-5385
Mitre link : CVE-2025-5385
CVE.ORG link : CVE-2025-5385
JSON object : View
Products Affected
huayi-tec
- jeewms
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')