A security vulnerability has been detected in kalcaddle kodbox 1.61. This affects the function fileGet/fileSave of the file app/controller/explorer/editor.class.php. The manipulation of the argument path leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Fri, 12 Sep 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Kodcloud
Kodcloud kodbox
CPEs cpe:2.3:a:kodcloud:kodbox:1.61:*:*:*:*:*:*:*
Vendors & Products Kodcloud
Kodcloud kodbox

Thu, 11 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 11 Sep 2025 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Kalcaddle
Kalcaddle kodbox
Vendors & Products Kalcaddle
Kalcaddle kodbox

Wed, 10 Sep 2025 23:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in kalcaddle kodbox 1.61. This affects the function fileGet/fileSave of the file app/controller/explorer/editor.class.php. The manipulation of the argument path leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title kalcaddle kodbox editor.class.php fileSave path traversal
Weaknesses CWE-22
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-09-10T23:02:05.674Z

Updated: 2025-09-11T14:29:03.494Z

Reserved: 2025-09-10T13:42:42.775Z

Link: CVE-2025-10233

cve-icon Vulnrichment

Updated: 2025-09-11T14:28:58.472Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-10T23:15:33.830

Modified: 2025-09-12T15:34:55.973

Link: CVE-2025-10233

cve-icon Redhat

No data.