Path Traversal Vulnerability in Four-Faith Water Conservancy Informatization Platform
CVE-2025-11018
Key Information:
- Vendor
Four-faith
- Vendor
- CVE Published:
- 26 September 2025
Badges
What is CVE-2025-11018?
A vulnerability exists in the Four-Faith Water Conservancy Informatization Platform version 1.0 that allows for path traversal attacks. This weakness arises from an insecure handling of the file argument in specific endpoints, such as /sysRole/index.do/../../generalReport/download.do and usrlogout.do.do. By manipulating the fileName parameter, an attacker could potentially access unauthorized files on the server. The exploit is capable of being executed remotely, raising significant security concerns. Despite early notification, the vendor has not addressed this flaw.
Affected Version(s)
Water Conservancy Informatization Platform 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved