A vulnerability, which was classified as problematic, was...
Moderate severity
Unreviewed
Published
May 31, 2025
to the GitHub Advisory Database
•
Updated May 31, 2025
Description
Published by the National Vulnerability Database
May 31, 2025
Published to the GitHub Advisory Database
May 31, 2025
Last updated
May 31, 2025
A vulnerability, which was classified as problematic, was found in Yifang CMS up to 2.0.2. Affected is the function downloadFile of the file /api/File/downloadFile of the component Admin Panel. The manipulation of the argument File leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
References