Metrics
Affected Vendors & Products
Wed, 08 Oct 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Four-faith
Four-faith water Conservancy Informatization |
|
CPEs | cpe:2.3:a:four-faith:water_conservancy_informatization:1.0:*:*:*:*:*:*:* | |
Vendors & Products |
Four-faith
Four-faith water Conservancy Informatization |
Fri, 26 Sep 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 26 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw has been found in Four-Faith Water Conservancy Informatization Platform 1.0. This affects an unknown function of the file /sysRole/index.do/../../generalReport/download.do;usrlogout.do.do. Executing manipulation of the argument fileName can lead to path traversal. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | Four-Faith Water Conservancy Informatization Platform download.do;usrlogout.do.do path traversal | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-09-26T14:02:08.786Z
Updated: 2025-09-26T15:05:42.856Z
Reserved: 2025-09-26T06:53:24.148Z
Link: CVE-2025-11018

Updated: 2025-09-26T15:05:25.154Z

Status : Analyzed
Published: 2025-09-26T14:15:42.270
Modified: 2025-10-08T20:24:44.240
Link: CVE-2025-11018

No data.