CVE-2025-5380 is a critical path traversal vulnerability in ashinigit 天青一白 XueShengZhuSu 学生住宿管理系统, specifically within the image file upload component. An authenticated attacker can remotely exploit this flaw by manipulating the "File" argument during an upload to traverse directories. While the CVSS score is 6.3 (Medium), the public disclosure of an exploit and remote attack vector indicate a significant risk. There is currently no evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Ashinigit 天青一白 | XueShengZhuSu 学生住宿管理系统 | 4d3f0ada0e71482c1e51fd5f5615e5a3d8bcbfbbCNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.