Path Traversal Vulnerability in Aviation Weather Plugin by NOAA
CVE-2025-28980
7.7HIGH
What is CVE-2025-28980?
The Aviation Weather plugin from NOAA is susceptible to a path traversal vulnerability, which could allow an attacker to manipulate file paths and access restricted files on the server. This flaw affects versions from n/a to 0.7.2, potentially enabling unauthorized file deletion or exposure of sensitive information. Website administrators are highly encouraged to update to the latest version and implement appropriate security measures to mitigate this risk.
Affected Version(s)
Aviation Weather from NOAA <= 0.7.2