PT-2026-5702 · Unknown · Com.Xiaoleilu.Loserver+1
CVE-2025-66480
·
Publicado
2026-02-02
·
Atualizado
2026-03-03
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Wildfire IM versions prior to 1.4.3
Description
Wildfire IM’s im-server component contains a critical issue in the file upload functionality within com.xiaoleilu.loServer.action.UploadFileAction. The application exposes an API endpoint ''/fs'' that handles multipart file uploads but does not properly sanitize the filename provided by the user. The
writeFileUploadData method directly concatenates the configured storage directory with the filename from the upload request without removing directory traversal sequences. This allows an attacker to write arbitrary files to any location on the server's filesystem where the application process has write permissions, potentially leading to Remote Code Execution (RCE).Recommendations
Update Wildfire IM to version 1.4.3 or later.
Exploit
Correção
RCE
Path traversal
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Wildfire Im
Com.Xiaoleilu.Loserver