ZeroHour

CVE-2025-67076

CVSS 3.1
7.5 high
EPSS
<1%p56
Published
()
Modified
Description

Directory traversal vulnerability in Omnispace Agora Project before 25.10 allowing unauthenticated attackers to read files on the system via the misc controller and the ExternalGetFile action. Only files with an extension can be read.

Vendors
agora-project
Products
agora-project
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.