CVE-2025-7575 Details
Description
A vulnerability has been found in Zavy86 WikiDocs up to 1.0.77 and classified as critical. Affected by this vulnerability is the function image_drop_upload_ajax/image_delete_ajax of the file submit.php. The manipulation leads to path traversal. The attack can be launched remotely. Upgrading to version 1.0.78 is able to address this issue. The identifier of the patch is 98ea9ee4a2052c4327f89d2f7688cc1b5749450d. It is recommended to upgrade the affected component.
A critical path traversal vulnerability has been identified in Zavy86 WikiDocs versions through 1.0.77. The issue arises in the submit.php file, specifically within the image_drop_upload_ajax and image_delete_ajax functions. The vulnerability allows authenticated administrators to delete arbitrary files on the server by exploiting improper sanitization of user-supplied file names, enabling the manipulation of file paths to traverse outside of intended directories. This vulnerability can be exploited remotely, but requires administrator-level authentication.
Users are advised to upgrade to Zavy86 WikiDocs version 1.0.78, which addresses this vulnerability. The updated version is available on the Zavy86 WikiDocs GitHub releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 14, 2025CISA-ADP
Assessed Jul 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/?submit.609096 | CISA-ADP | ExploitTechnical Description |
| https://github.com/Zavy86/WikiDocs/commit/98ea9ee4a2052c4327f89d2f7688cc1b5749450d | [email protected] | Source CodeVendor |
| https://github.com/Zavy86/WikiDocs/pull/258 | [email protected] | Issue TrackingVendor |
| https://github.com/Zavy86/WikiDocs/releases/tag/1.0.78 | [email protected] | Release NotesVendor |
| https://vuldb.com/?ctiid.316273 | [email protected] | AdvisoryRemedy |
| https://vuldb.com/?id.316273 | [email protected] | AdvisoryRemedy |
| https://vuldb.com/?submit.609096 | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Zavy86 WikiDocs | <= 1.0.77 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2025 | CVE Modified | CISA-ADP |
| Jul 14, 2025 | New CVE Received | [email protected] |
Volerion