CVE-2025-41428

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in TimeWorks 10.0 to 10.3. If exploited, arbitrary JSON files on the server may be viewed by a remote unauthenticated attacker.
Configurations

No configuration.

History

04 Jun 2025, 14:54

Type Values Removed Values Added
Summary
  • (es) Existe un problema de limitación incorrecta de una ruta de acceso a un directorio restringido («Path Traversal») en TimeWorks 10.0 a 10.3. Si se explota, un atacante remoto no autenticado podría acceder a archivos JSON arbitrarios en el servidor.

03 Jun 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-03 08:15

Updated : 2025-06-04 14:54


NVD link : CVE-2025-41428

Mitre link : CVE-2025-41428

CVE.ORG link : CVE-2025-41428


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')