CVE-2025-3686

A vulnerability classified as problematic was found in misstt123 oasys 1.0. Affected by this vulnerability is the function image of the file /show. The manipulation leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.
References
Link Resource
https://github.com/misstt123/oasys/issues/10 Exploit Issue Tracking Vendor Advisory
https://vuldb.com/?ctiid.304975 Permissions Required VDB Entry
https://vuldb.com/?id.304975 Third Party Advisory VDB Entry
https://vuldb.com/?submit.553372 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:misstt123:oasys:1.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-04-16 12:15

Updated : 2025-06-25 18:53


NVD link : CVE-2025-3686

Mitre link : CVE-2025-3686

CVE.ORG link : CVE-2025-3686


JSON object : View

Products Affected

misstt123

  • oasys
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')