CVE-2025-2305HIGH 8.6EPSS p24.2%
CVE-2025-2305CVE-2025-2305
Description
A Path traversal vulnerability in the file
download functionality was identified. This vulnerability allows
unauthenticated users to download arbitrary files, in the context of the
application server, from the Linux server.
Scoring
| CVSS 3.1 | 8.6 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
| EPSS | 0.33% probability of exploitation · percentile 24.2% · 2026-06-18T12:00:27Z |
| Published | 2025-05-16 |
| Last modified | 2026-04-15 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Input Validationcwe-20 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.