First published: Wed Jan 22 2025(Updated: )
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NotFound XLSXviewer allows Path Traversal. This issue affects XLSXviewer: from n/a through 2.1.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound XLSXviewer | <=2.1.1 | |
WordPress XLSX Viewer | <=2.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23562 is classified as a Path Traversal vulnerability, which can lead to unauthorized access to files on the server.
To fix CVE-2025-23562, update NotFound XLSXviewer to version 2.1.2 or later to patch the vulnerability.
CVE-2025-23562 affects NotFound XLSXviewer versions up to and including 2.1.1.
Yes, WordPress XLSXviewer versions up to and including 2.1.1 are also affected by CVE-2025-23562.
CVE-2025-23562 can allow attackers to read or manipulate files on the server, potentially leading to data breaches.