First published: Sun May 18 2025(Updated: )
A vulnerability was found in merikbest ecommerce-spring-reactjs up to 464e610bb11cc2619cf6ce8212ccc2d1fd4277fd. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/v1/admin/ of the component File Upload Endpoint. The manipulation of the argument filename leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
merikbest ecommerce-spring-reactjs | <=464e610bb11cc2619cf6ce8212ccc2d1fd4277fd |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-4868 has been rated as critical.
CVE-2025-4868 affects the File Upload Endpoint functionality in the /api/v1/admin/ file.
To fix CVE-2025-4868, update the merikbest ecommerce-spring-reactjs software to a version beyond 464e610bb11cc2619cf6ce8212ccc2d1fd4277fd.
CVE-2025-4868 affects versions of the merikbest ecommerce-spring-reactjs software up to and including version 464e610bb11cc2619cf6ce8212ccc2d1fd4277fd.
CVE-2025-4868 involves vulnerabilities related to file upload functionalities.