Beveiligingsadvies

CVE-2018-25408

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-05-30 14:55:15
Laatst bijgewerkt 2026-06-01 14:48:21
Toegewezen door VulnCheck
CVSS-score 8.7
Status PUBLISHED

Beschrijving

The Open ISES Project 3.30A contains a path traversal vulnerability in the ajax/download.php endpoint that allows unauthenticated attackers to download arbitrary files by manipulating the filename parameter. Attackers can supply directory traversal sequences ../ in the filename parameter to access files outside the intended directory, including configuration files and system files.