Directory Traversal Vulnerability in Performave Convoy Management Panel
CVE-2025-52562
10CRITICAL
What is CVE-2025-52562?
A directory traversal vulnerability in the LocaleController component of Performave Convoy allows unauthenticated remote attackers to exploit the system. By sending a specially crafted HTTP request that includes malicious locale and namespace parameters, an attacker can include and execute arbitrary PHP files stored on the server. This vulnerability affects Convoy versions 3.9.0-rc3 up to, but not including version 4.4.1, which has received a patch. To mitigate this vulnerability temporarily, implementing strict Web Application Firewall (WAF) rules on incoming requests targeting the affected endpoints is advised.
Affected Version(s)
panel >= 3.9.0-rc.3, < 4.4.1