First published: Mon Mar 03 2025(Updated: )
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NotFound Sports Rankings and Lists allows Absolute Path Traversal. This issue affects Sports Rankings and Lists: from n/a through 1.0.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound Sports Rankings and Lists | >n/a<=1.0.2 | |
NotFound Sports Rankings and Lists | <=2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25162 is a high severity vulnerability that allows for absolute path traversal in NotFound Sports Rankings and Lists.
To fix CVE-2025-25162, upgrade NotFound Sports Rankings and Lists to version 1.0.3 or later.
CVE-2025-25162 affects NotFound Sports Rankings and Lists versions from n/a to 1.0.2.
Yes, CVE-2025-25162 can be exploited remotely due to the improper limitation of a pathname.
The exploitation of CVE-2025-25162 could lead to unauthorized access to sensitive files on the server.