CVE-2025-54769 Information

Description

An authenticated read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrite existing PERL modules within the application to achieve remote code execution (RCE) by an attacker.

Reference

https://korelogic.com/Resources/Advisories/KL-001-2025-016.txt https://lpar2rrd.com/note800.php

CNNVD-202507-3572 (Published: 2025-07-29)

Share on: