CVE-2025-4893 is a critical path traversal vulnerability found in the uploadLocalImage function within the File Upload Endpoint of jammy928 CoinExchange_CryptoExchange_Java, specifically affecting versions up to commit 8adf508b996020d3efbeeb2473d7235bd01436fa. This flaw allows an authenticated attacker to manipulate the filename argument, potentially leading to unauthorized file access, modification, or creation on the server. The vulnerability has a CVSS score of 6.3 (Medium), indicating a network-based attack with low complexity, requiring low privileges, and resulting in low impact to confidentiality, integrity, and availability. While the exploit has been publicly disclosed, there is currently no evidence of active exploitation, nor are there known Metasploit, Nuclei, or ExploitDB modules available. Community discussion and media coverage for this CVE are minimal, which is typical for a large percentage of reported vulnerabilities. Despite the public disclosure, the low EPSS score suggests a low probability of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Jammy928 | CoinExchange CryptoExchange Java | 8adf508b996020d3efbeeb2473d7235bd01436faCNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.