Directory traversal vulnerability in NextChat thru 2.16.0 due to the WebDAV proxy failing to canonicalize or reject dot path segments in its catch-all route, allowing attackers to gain sensitive information via authenticated or anonymous WebDAV endpoints.
                
            Metrics
Affected Vendors & Products
Advisories
    No advisories yet.
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Mon, 03 Nov 2025 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-22 | |
| Metrics | 
        
        cvssV3_1
         
 
  | 
Mon, 03 Nov 2025 20:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Directory traversal vulnerability in NextChat thru 2.16.0 due to the WebDAV proxy failing to canonicalize or reject dot path segments in its catch-all route, allowing attackers to gain sensitive information via authenticated or anonymous WebDAV endpoints. | |
| References | 
         | 
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-03T20:11:16.719Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-50735
Updated: 2025-11-03T20:10:40.552Z
Status : Received
Published: 2025-11-03T20:19:12.553
Modified: 2025-11-03T21:19:37.790
Link: CVE-2025-50735
No data.
                        OpenCVE Enrichment
                    No data.