CVE-2025-2961
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Mar 30, 2025
Updated: Apr 1, 2025
CWE ID 24
CWE ID 23
Summary
CVE-2025-2961 is a newly disclosed vulnerability affecting opensolon up to version 3.1.0. The issue lies within the function "render_mav" of the "/aa" file in the component "org.noear.solon.core.handle.RenderManager". An attacker can manipulate the argument "template" with the input "../org/example/HelloApp.class" to traverse paths and access sensitive files located in the "../filedir" directory. This vulnerability can be exploited remotely. The existence and exploit details have been made public.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.