CVE Details
Basic Information
| Title | javahongxi whatsmars InitializrController.java initialize path traversal |
|---|---|
| Type | cve |
| Published | 2025-06-16T06:00:10.880Z |
| Last Seen |
Product Information
| Vendor | javahongxi |
|---|---|
| Product | whatsmars |
| Version | 2021.4.0 |
CVSS Information
| Base Score | 5.3 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | A path traversal vulnerability exists in the initialize function of the InitializrController.java file in javahongxi whatsmars 2021.4.0. This allows remote attackers to potentially access arbitrary files on the server. The vendor was contacted but did not respond. |
|---|---|
| AI Severity | Medium |
| Vendor | javahongxi |
| Product | whatsmars |
| Affected Version | 2021.4.0 |
Affected Products
- javahongxi whatsmars 2021.4.0
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-22 |
| Bulletin Family |
References
Description
A vulnerability was found in javahongxi whatsmars 2021.4.0. It has been rated as problematic. Affected by this issue is the function initialize of the file /whatsmars-archetypes/whatsmars-initializr/src/main/java/org/hongxi/whatsmars/initializr/controller/InitializrController.java. The manipulation of the argument artifactId leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.