CVE-2025-24891

CVSS 3.1 Score 9.6 of 10 (high)

Details

Published Jan 31, 2025
CWE ID 22
CWE ID 276

Summary

CVE-2025-24891 is a path traversal vulnerability affecting Dumb Drop, a file upload application. This issue allows users with upload permissions to overwrite system files arbitrarily, as the container runs with root privileges by default. malicious payloads can be injected into files that run on schedule or upon specific service actions, potentially granting unprivileged users root access. The vulnerability exists even when authentication is not required.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share