CVE-2025-12923
10.11.2025, 01:15
A vulnerability was determined in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function resourceDownload of the file /dev-api/common/download. Executing manipulation of the argument path can lead to path traversal. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
| Vendor | Product | Version |
|---|---|---|
| 1000mz | chestnutcms | 𝑥 ≤ 1.5.8 |
𝑥
= Vulnerable software versions