CVE-2025-0703 Details
Description
A vulnerability, which was classified as problematic, has been found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. This issue affects some unknown processing of the file src/main/java/io/github/controller/SysFileController.java. The manipulation of the argument name leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.
A path traversal vulnerability has been identified in JoeyBling Bootplus versions up to commit 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. The issue arises in the file 'src/main/java/io/github/controller/SysFileController.java', where the download method fails to properly validate the 'name' parameter. This lack of input sanitization allows for the manipulation of file paths, enabling remote attackers to download arbitrary files from the server.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/JoeyBling/bootplus/issues/25 | [email protected] | Not Applicable |
| https://github.com/JoeyBling/bootplus/issues/25#issue-2786928618 | [email protected] | Not Applicable |
| https://vuldb.com/?ctiid.293231 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.293231 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.480842 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| joeybling bootplus | <= 2020-08-24 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 10, 2025 | Initial Analysis | [email protected] |
| Jan 24, 2025 | New CVE Received | [email protected] |