Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-20499 | The iPublish System developed by Jhenggao has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to read arbitrary system file. |
Solution
For school running the system on-premises, please contact the vendor to confirm the update status, or consider disabling external access and limiting use to within the campus only.
Workaround
No workaround given by the vendor.
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 08 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Jul 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The iPublish System developed by Jhenggao has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to read arbitrary system file. | |
| Title | Jhenggao iPublish System - Arbitrary File Reading through Path Traversal | |
| Weaknesses | CWE-23 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-07-08T14:05:31.209Z
Reserved: 2025-07-07T03:50:37.980Z
Link: CVE-2025-7146
Updated: 2025-07-08T14:05:23.605Z
Status : Awaiting Analysis
Published: 2025-07-08T02:15:22.367
Modified: 2025-07-08T16:18:14.207
Link: CVE-2025-7146
No data.
OpenCVE Enrichment
Updated: 2025-07-13T22:31:25Z
EUVD