CVE-2019-25087 is a critical path traversal vulnerability affecting the RamseyK httpserver project, specifically within the ResourceHost::getResource function in src/ResourceHost.cpp. An unauthenticated attacker can remotely manipulate the URI argument using '../filedir' sequences to access arbitrary files on the server. This vulnerability carries a CVSS v3.1 score of 7.5 (HIGH), indicating a high impact on confidentiality with no integrity or availability impact. The attack vector is network-based with low attack complexity, requiring no user interaction or privileges. While the EPSS score is low, suggesting a low probability of exploitation, the FAUCET Risk Score is 51/100, indicating moderate risk. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, typical for a large percentage of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2019-09-08CPE matchmatch criteria | cpe:2.3:a:httpserver_project:httpserver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.