CVE-2025-3686

A vulnerability classified as problematic was found in misstt123 oasys 1.0. Affected by this vulnerability is the function image of the file /show. The manipulation leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.
References
Link Resource
https://github.com/misstt123/oasys/issues/10 Exploit Issue Tracking Vendor Advisory
https://vuldb.com/?ctiid.304975 Permissions Required VDB Entry
https://vuldb.com/?id.304975 Third Party Advisory VDB Entry
https://vuldb.com/?submit.553372 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:misstt123:oasys:1.0:*:*:*:*:*:*:*

History

25 Jun 2025, 18:53

Type Values Removed Values Added
CPE cpe:2.3:a:misstt123:oasys:1.0:*:*:*:*:*:*:*
First Time Misstt123
Misstt123 oasys
References () https://github.com/misstt123/oasys/issues/10 - () https://github.com/misstt123/oasys/issues/10 - Exploit, Issue Tracking, Vendor Advisory
References () https://vuldb.com/?ctiid.304975 - () https://vuldb.com/?ctiid.304975 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.304975 - () https://vuldb.com/?id.304975 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.553372 - () https://vuldb.com/?submit.553372 - Third Party Advisory, VDB Entry
Summary
  • (es) Se encontró una vulnerabilidad clasificada como problemática en misstt123 oasys 1.0. Esta vulnerabilidad afecta la imagen de función del archivo /show. La manipulación provoca un Path Traversal. El ataque puede ejecutarse remotamente. Se ha hecho público el exploit y puede que sea utilizado. Este producto no utiliza control de versiones. Por ello, no se dispone de información sobre las versiones afectadas y no afectadas.

16 Apr 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-16 12:15

Updated : 2025-06-25 18:53


NVD link : CVE-2025-3686

Mitre link : CVE-2025-3686

CVE.ORG link : CVE-2025-3686


JSON object : View

Products Affected

misstt123

  • oasys
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')