Path Traversal Vulnerability in kalcaddle kodbox by kalcaddle
CVE-2025-10233
Key Information:
Badges
What is CVE-2025-10233?
A security vulnerability has been identified in kalcaddle kodbox version 1.61, specifically within the file handling functions located in app/controller/explorer/editor.class.php. The issue arises due to inadequate input validation on the 'path' argument in the fileGet and fileSave functions, which permits adversaries to perform path traversal attacks. This vulnerability enables unauthorized access and manipulation of filesystem directories and files, allowing potential exploitation from a remote location. Despite the public disclosure of this flaw, the vendor did not respond to initial communications regarding the issue, raising concerns about the urgency of a remediation.
Affected Version(s)
kodbox 1.61
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved