ZeroHour

CVE-2025-54769

PoC
CVSS 3.1
8.8 high
EPSS
3%p88
Published
()
Modified
Description

An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrite existing PERL modules within the application to achieve remote code execution (RCE) by an attacker.

Vendors
xorux
Products
lpar2rrd
Weakness
CWE-24, CWE-434, CWE-648
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.