Path Traversal Vulnerability in Jeewms by Guangzhou Huayi Intelligent Technology
CVE-2025-0390
Key Information:
- Vendor
- Guangzhou Huayi Intelligent Technology
- Status
- Jeewms
- Vendor
- CVE Published:
- 11 January 2025
Badges
Summary
A path traversal vulnerability in Jeewms by Guangzhou Huayi Intelligent Technology allows an attacker to manipulate file paths within the application. This vulnerability affects the /wmOmNoticeHController.do file and can be exploited remotely. Attackers may exploit this flaw to access unauthorized files by using ../filedir
in their requests. Users are advised to upgrade to version 20250101 to mitigate this security risk, as it addresses the vulnerability effectively.
Affected Version(s)
Jeewms 20241229
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved