CVE-2025-8048: External Control of File path vulnerability has been discovered on Openext Flipper.
External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal. The vulnerability could allow a user to submit a stored local file path and then download the specified file from the system by requesting the stored document ID.
This issue affects Flipper: 3.1.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8048?
CVE-2025-8048 is classified as a moderate severity vulnerability due to its potential for path traversal exploits.
How does CVE-2025-8048 impact OpenText Flipper?
CVE-2025-8048 allows an attacker to submit a stored local file path and download sensitive files from the system using the stored document ID.
What versions of OpenText Flipper are affected by CVE-2025-8048?
CVE-2025-8048 affects all versions of OpenText Flipper that are vulnerable to path traversal attacks.
How do I fix CVE-2025-8048?
To fix CVE-2025-8048, ensure that proper validation and sanitization of file paths are implemented to prevent unauthorized access.
Is CVE-2025-8048 easy to exploit?
Yes, CVE-2025-8048 can be easily exploited if proper security measures are not in place to restrict access to file paths.