Mite for Perl before 0.013000 generates code with the current working directory ('.') added to the @INC path similar to CVE-2016-1238.
If an attacker can place a malicious file in current working directory, it may be
loaded instead of the intended file, potentially leading to arbitrary
code execution.
This affects the Mite distribution itself, and other distributions that contain code generated by Mite.
References
Configurations
No configuration.
History
01 Apr 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
01 Apr 2025, 02:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-01 02:15
Updated : 2025-04-01 20:26
NVD link : CVE-2025-30672
Mitre link : CVE-2025-30672
CVE.ORG link : CVE-2025-30672
JSON object : View
Products Affected
No product.
CWE
CWE-427
Uncontrolled Search Path Element