CVE-2025-51539 (CNNVD-202508-2113)
中文标题:
EzGED 安全漏洞
英文标题:
EzGED3 3.5.0 contains an unauthenticated arbitrary file read vulnerability due to improper access co...
漏洞描述
中文描述:
EzGED是法国EzGED公司的一个企业级电子文件管理系统。 EzGED 3.5.0版本存在安全漏洞,该漏洞源于访问控制和输入验证不足,可能导致任意文件读取。
英文描述:
EzGED3 3.5.0 contains an unauthenticated arbitrary file read vulnerability due to improper access control and insufficient input validation in a script exposed via the web interface. A remote attacker can supply a crafted path parameter to a PHP script to read arbitrary files from the filesystem. The script lacks both authentication checks and secure path handling, allowing directory traversal attacks (e.g., ../../../) to access sensitive files such as configuration files, database dumps, source code, and password reset tokens. If phpMyAdmin is exposed, extracted credentials can be used for direct administrative access. In environments without such tools, attacker-controlled file reads still allow full database extraction by targeting raw MySQL data files. The vendor states that the issue is fixed in 3.5.72.27183.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| ezged | ezged3 | * | - | - |
cpe:2.3:a:ezged:ezged3:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
3.1 (adp)
MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-51539 |
2025-11-11 15:23:27 | 2025-11-11 07:40:39 |
| NVD | nvd_CVE-2025-51539 |
2025-11-11 15:00:59 | 2025-11-11 07:48:27 |
| CNNVD | cnnvd_CNNVD-202508-2113 |
2025-11-11 15:12:54 | 2025-11-11 08:00:06 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202508-2113
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 0 -> 1
- data_sources: ['cve'] -> ['cve', 'nvd']