Impact
The flaw stems from insufficient validation of the path parameter in the FileController component of yeqifu warehouse. By supplying a crafted path string containing traversal sequences, an attacker can cause the application to open files located outside the intended directory. This allows reading of confidential data stored on the server. The weakness is a classic directory traversal, classified as CWE‑22.
Affected Systems
The vulnerability applies to any deployment of the yeqifu warehouse application that incorporates the FileController that existed up to commit aaf29962ba407d22d991781de28796ee7b4670e4. Exact version numbers are not available because the product follows a rolling release model and the vendor has not disclosed a fix or an update schedule.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, so the exploitation probability is uncertain but an exploit has been publicly disclosed. Attackers can trigger the flaw remotely by sending crafted HTTP requests; no local privileges or user interaction are required. Successful exploitation permits reading of arbitrary files, which may expose sensitive information and enable further attacks if additional vulnerabilities exist.
OpenCVE Enrichment