First published: Sun May 11 2025(Updated: )
A vulnerability was found in feng_ha_ha/megagao ssm-erp and production_ssm 1.0. It has been declared as problematic. Affected by this vulnerability is the function handleFileDownload of the file FileController.java of the component File Handler. The manipulation leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product is distributed under two entirely different names.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
ssm-erp | ||
ssm-erp |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-4530 has been declared as a problematic vulnerability due to its impact on the File Handler component.
To fix CVE-2025-4530, review and update the FileController.java to prevent path traversal vulnerabilities.
CVE-2025-4530 affects the feng_ha_ha megagao ssm-erp and production_ssm applications.
CVE-2025-4530 is a path traversal vulnerability that can lead to unauthorized file access.
The affected function in CVE-2025-4530 is handleFileDownload within the FileController.java file.