CVE-2025-27413 is a path traversal vulnerability affecting PwnDoc versions prior to 1.2.0, allowing an administrator to import raw data containing directory traversal sequences into the database. This flaw, when combined with the template update functionality, enables overwriting arbitrary files on the filesystem, including source code, potentially leading to Remote Code Execution. The vulnerability has a CVSS score of 4.9 (MEDIUM) due to its network attack vector and high impact on integrity, though it requires high privileges for exploitation. There is currently no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.0CPE matchmatch criteria | cpe:2.3:a:pwndoc_project:pwndoc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.