CVE-2025-30882

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 1, 2025
CWE ID 22

Summary

CVE-2025-30882 is a Path Traversal vulnerability affecting the JoomSky JS Help Desk software. The issue arises from a failure to properly limit file paths to restricted directories, allowing an attacker to traverse and potentially access sensitive files. This vulnerability exists in all versions of JS Help Desk from n/a to 2.9.1, posing a significant risk to users running outdated software. An attacker could exploit this flaw to gain unauthorized access to system data, potentially leading to data theft or unintended modifications. It is strongly recommended that users of JoomSky JS Help Desk upgrade to the latest patched version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share