VulnerabilityAnalyzed
CVE-2025-6453
A vulnerability classified as critical has been found in diyhi bbs 6.8.
LOW 2.1EPSS 0.41%
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability classified as critical has been found in diyhi bbs 6.8. Affected is the function Add of the file /src/main/java/cms/web/action/template/ForumManageAction.java of the component API. The manipulation of the argument dirName leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
- CVSS 4.0
- 2.1 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.41% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- diyhi/bbs
- Source
- cna@vuldb.com
References
- https://github.com/ShenxiuSec/cve-proofs/blob/main/POC-20250618-01.mdExploit
- https://github.com/ShenxiuSec/cve-proofs/blob/main/POC-20250618-01.md#steps-to-reproduceExploit
- https://vuldb.com/?ctiid.313560Permissions Required, VDB Entry
- https://vuldb.com/?id.313560Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.598862Third Party Advisory, VDB Entry
- https://github.com/ShenxiuSec/cve-proofs/blob/main/POC-20250618-01.mdExploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.