CVE-2025-3381

A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu 4.2.0. This affects an unknown part of the file WebIMController.java of the component File Upload. The manipulation of the argument ID leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
References
Link Resource
https://github.com/mapl3miss/uckefuVul/blob/main/uckefu-upload.md Exploit Third Party Advisory
https://vuldb.com/?ctiid.303627 Permissions Required VDB Entry
https://vuldb.com/?id.303627 Third Party Advisory VDB Entry
https://vuldb.com/?submit.552369 Third Party Advisory VDB Entry
https://github.com/mapl3miss/uckefuVul/blob/main/uckefu-upload.md Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:zhangyanbo2007:youkefu:4.2.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-04-07 20:15

Updated : 2025-10-10 12:44


NVD link : CVE-2025-3381

Mitre link : CVE-2025-3381

CVE.ORG link : CVE-2025-3381


JSON object : View

Products Affected

zhangyanbo2007

  • youkefu
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')