CVE-2025-24891
CVSS 3.1 Score 9.6 of 10 (high)
Details
Published Jan 31, 2025
CWE ID 22
CWE ID 276
Summary
CVE-2025-24891 is a path traversal vulnerability affecting Dumb Drop, a file upload application. This issue allows users with upload permissions to overwrite system files arbitrarily, as the container runs with root privileges by default. malicious payloads can be injected into files that run on schedule or upon specific service actions, potentially granting unprivileged users root access. The vulnerability exists even when authentication is not required.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.