CVE-2025-30882
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-30882 is a Path Traversal vulnerability affecting the JoomSky JS Help Desk software. The issue arises from a failure to properly limit file paths to restricted directories, allowing an attacker to traverse and potentially access sensitive files. This vulnerability exists in all versions of JS Help Desk from n/a to 2.9.1, posing a significant risk to users running outdated software. An attacker could exploit this flaw to gain unauthorized access to system data, potentially leading to data theft or unintended modifications. It is strongly recommended that users of JoomSky JS Help Desk upgrade to the latest patched version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.