CVE-2025-3718: Client-side path traversal in Guardian/CMC before 25.2.0
A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing validation of an input parameter. An authenticated user with limited privileges can craft a malicious URL which, if visited by an authenticated victim, leads to a Cross-Site Scripting (XSS) attack.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3718?
CVE-2025-3718 is categorized as a medium severity vulnerability due to its client-side nature allowing unauthorized access to sensitive information.
How do I fix CVE-2025-3718?
To fix CVE-2025-3718, update Guardian CMC to version 25.2.1 or later, which includes the necessary validation for input parameters.
Who is affected by CVE-2025-3718?
Authenticated users of Guardian CMC versions up to 25.2.0 are affected by CVE-2025-3718 due to the missing input validation.
Can CVE-2025-3718 be exploited remotely?
Yes, CVE-2025-3718 can be exploited remotely if an authenticated user visits a crafted URL from a malicious source.
What is the nature of the vulnerability in CVE-2025-3718?
CVE-2025-3718 is a client-side path traversal vulnerability that allows crafted URLs to bypass security and access restricted files.