Path Traversal Vulnerability in yeqifu carRental Service
CVE-2025-9650
Key Information:
Badges
What is CVE-2025-9650?
A path traversal vulnerability exists in the yeqifu carRental application's removeFileByPath function located in AppFileUtils.java. This vulnerability allows attackers to manipulate the carimg argument, potentially executing remote file deletion. The nature of this flaw means that it could be exploited by unauthorized users to access sensitive files beyond the intended directories. The exploit has been made publicly available, emphasizing the urgency for users of the affected versions to apply mitigations to their systems.
Affected Version(s)
carRental 3fabb7eae93d209426638863980301d6f99866b3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved