CVE-2022-25773

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Feb 26, 2025
CWE ID 22

Summary

CVE-2022-25773 is a file placement vulnerability that poses a risk to servers. The issue lies in the asset upload functionality, which fails to restrict users from uploading files to directories beyond the intended temporary directory. As a result, unintended assets can be uploaded to server directories, potentially leading to security breaches. This vulnerability falls under the category of Improper Limitation of a Pathname to a Restricted Directory. Addressing this issue is essential to maintaining the security and integrity of affected systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share