A vulnerability was found in weibocom rill-flow 0.1.18. It has been classified as critical. Affected is an unknown function of the component Management Console. The manipulation leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
References
Link | Resource |
---|---|
https://github.com/weibocom/rill-flow/issues/102 | Exploit Issue Tracking |
https://github.com/weibocom/rill-flow/issues/102#issue-2933822293 | Exploit |
https://vuldb.com/?ctiid.309408 | Permissions Required VDB Entry |
https://vuldb.com/?id.309408 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.575478 | Exploit Third Party Advisory VDB Entry |
https://github.com/weibocom/rill-flow/issues/102 | Exploit Issue Tracking |
Configurations
History
12 Jun 2025, 16:28
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/weibocom/rill-flow/issues/102 - Exploit, Issue Tracking | |
References | () https://github.com/weibocom/rill-flow/issues/102#issue-2933822293 - Exploit | |
References | () https://vuldb.com/?ctiid.309408 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.309408 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.575478 - Exploit, Third Party Advisory, VDB Entry | |
CPE | cpe:2.3:a:weibo:rill-flow:0.1.18:*:*:*:*:*:*:* | |
First Time |
Weibo rill-flow
|
19 May 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/weibocom/rill-flow/issues/102 - |
19 May 2025, 13:35
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
18 May 2025, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-18 08:15
Updated : 2025-06-12 16:28
NVD link : CVE-2025-4866
Mitre link : CVE-2025-4866
CVE.ORG link : CVE-2025-4866
JSON object : View
Products Affected
- rill-flow