CVE-2025-5509: quequnlong shiyi-blog upload path traversal
Published Jun 3, 2025
·Updated
A vulnerability classified as critical has been found in quequnlong shiyi-blog up to 1.2.1. This affects an unknown part of the file /api/file/upload. The manipulation of the argument file/source leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
2 affected components
quequnlong shiyi-blog<1.2.1
quequnlong shiyi-blog<=1.2.1
Event History
Jun 3, 2025
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Jan 12, 57458
Event
via FIRST·08:12 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-5509?
CVE-2025-5509 is classified as a critical vulnerability.
2
How do I fix CVE-2025-5509?
To mitigate CVE-2025-5509, upgrade to a version of quequnlong shiyi-blog that is later than 1.2.1.
3
What type of vulnerability is CVE-2025-5509?
CVE-2025-5509 is a path traversal vulnerability.
4
Can CVE-2025-5509 be exploited remotely?
Yes, CVE-2025-5509 can be exploited remotely.
5
Which parts of the system are affected by CVE-2025-5509?
CVE-2025-5509 affects the file upload functionality in the /api/file/upload endpoint.