CVE-2025-3043
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Apr 1, 2025
CWE ID 284
Summary
CVE-2025-3043 is a critical vulnerability affecting GuoMinJim PersonManage 1.0. The issue lies in the preHandle function of the /login/ file, which can be exploited through manipulation of the Request argument. This vulnerability allows for remote path traversal, posing a significant security risk. The exploit for this vulnerability has been made public, increasing the threat level. GuoMinJim PersonManage employs rolling releases for continuous delivery, making it difficult to determine which versions are affected and which have been updated.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.