Path Traversal Vulnerability in yeqifu carRental Software
CVE-2025-15432

6.9MEDIUM

Key Information:

Vendor

Yeqifu

Status
Vendor
CVE Published:
2 January 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2025-15432?

A path traversal vulnerability exists in the yeqifu carRental system, specifically within the downloadShowFile function of the FileController component. This flaw allows attackers to manipulate file paths, potentially gaining unauthorized access to files on the server. The vulnerability can be exploited remotely, posing significant risks as it may lead to sensitive data exposure. Despite the project's rolling release model intended for continuous updates, version-specific information on patches or affected releases remains unclear. An issue report has alerted the project maintainers to this problem, yet no response has been documented as of yet.

Affected Version(s)

carRental 3fabb7eae93d209426638863980301d6f99866b3

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

mukyuuhate (VulDB User)
.
CVE-2025-15432 : Path Traversal Vulnerability in yeqifu carRental Software