CVE-2025-2363
A vulnerability classified as critical has been found in lenve VBlog up to 1.0.0.
Does this matter?
Lower severity and a low EPSS score (0.64%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability classified as critical has been found in lenve VBlog up to 1.0.0. Affected is the function uploadImg of the file blogserver/src/main/java/org/sang/controller/ArticleController.java. The manipulation of the argument filename leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- CVSS 4.0
- 5.3 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.64% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- lenve/vblog
- Source
- cna@vuldb.com
References
- https://vuldb.com/?ctiid.299862Permissions Required, VDB Entry
- https://vuldb.com/?id.299862Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.514721Third Party Advisory, VDB Entry
- https://www.notion.so/Arbitrary-File-Upload-Vulnerability-in-VBlog-1-0-0-1adc693918ed8067b19ed9c61381024bPermissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.