Metrics
Affected Vendors & Products
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 26 Sep 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 26 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw has been found in Four-Faith Water Conservancy Informatization Platform 1.0. This affects an unknown function of the file /sysRole/index.do/../../generalReport/download.do;usrlogout.do.do. Executing manipulation of the argument fileName can lead to path traversal. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | Four-Faith Water Conservancy Informatization Platform download.do;usrlogout.do.do path traversal | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-09-26T15:05:42.856Z
Reserved: 2025-09-26T06:53:24.148Z
Link: CVE-2025-11018

Updated: 2025-09-26T15:05:25.154Z

Status : Awaiting Analysis
Published: 2025-09-26T14:15:42.270
Modified: 2025-09-26T14:32:19.853
Link: CVE-2025-11018

No data.

No data.