CVE-2025-5714

A vulnerability was found in SoluçõesCoop iSoluçõesWEB up to 20250516. It has been classified as problematic. This affects an unknown part of the file /sys/up.upload.php of the component Profile Information Update. The manipulation of the argument nomeArquivo leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.
References
Link Resource
https://github.com/lfparizzi/CVE-SolucoesCoop Exploit Third Party Advisory
https://github.com/lfparizzi/CVE-SolucoesCoop?tab=readme-ov-file#path-traversal-and-forced-navigation-abuse Exploit Third Party Advisory
https://vuldb.com/?ctiid.311235 Permissions Required VDB Entry
https://vuldb.com/?id.311235 Third Party Advisory VDB Entry
https://vuldb.com/?submit.579509 Third Party Advisory VDB Entry
https://github.com/lfparizzi/CVE-SolucoesCoop Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:isolucoesweb:solucoescoop:*:*:*:*:*:*:*:*

History

01 Oct 2025, 15:30

Type Values Removed Values Added
CPE cpe:2.3:a:isolucoesweb:solucoescoop:*:*:*:*:*:*:*:*
First Time Isolucoesweb
Isolucoesweb solucoescoop
References () https://github.com/lfparizzi/CVE-SolucoesCoop - () https://github.com/lfparizzi/CVE-SolucoesCoop - Exploit, Third Party Advisory
References () https://github.com/lfparizzi/CVE-SolucoesCoop?tab=readme-ov-file#path-traversal-and-forced-navigation-abuse - () https://github.com/lfparizzi/CVE-SolucoesCoop?tab=readme-ov-file#path-traversal-and-forced-navigation-abuse - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.311235 - () https://vuldb.com/?ctiid.311235 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.311235 - () https://vuldb.com/?id.311235 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.579509 - () https://vuldb.com/?submit.579509 - Third Party Advisory, VDB Entry

09 Jun 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-06 04:15

Updated : 2025-10-01 15:30


NVD link : CVE-2025-5714

Mitre link : CVE-2025-5714

CVE.ORG link : CVE-2025-5714


JSON object : View

Products Affected

isolucoesweb

  • solucoescoop
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')