CVE-2025-54769
HIGH 8.8EPSS 3.1%
An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrite existing PERL modules within the application to achieve remote code execution (RCE) by an attacker.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 3.11% chance of exploitation in the next 30 days, 87th percentile
- Published
- 2025-07-28
- Updated
- 2025-11-03
Proof-of-concept exploits (2)
- https://korelogic.com/Resources/Advisories/KL-001-2025-016.txt
- byteReaper77/CVE-2025-547692★ · 2025-07-30