CVE 5.3 MEDIUM

openviglet shio ShStaticFileAPI.java shStaticFilePreUpload path traversal_CVE-2025-8343

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was found in openviglet shio up to 0.3.8. It has been rated as critical. This issue affects the function shStaticFilePreUpload of the file shio-app/src/main/java/com/viglet/shio/api/staticfile/ShStaticFileAPI.java. The manipulation of the argument fileName leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

Basic Information

ID CVE-2025-8343
Source VulDB
Published Jul 31, 2025 at 01:02
Modified Jul 31, 2025 at 14:33

Affected Product

Vendor openviglet
Product shio
Version 0.3.0
Affected Versions openviglet shio 0.3.0
openviglet shio 0.3.1
openviglet shio 0.3.2
openviglet shio 0.3.3
openviglet shio 0.3.4
openviglet shio 0.3.5
openviglet shio 0.3.6
openviglet shio 0.3.7
openviglet shio 0.3.8

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.