A vulnerability classified as critical has been found in diyhi bbs 6.8. Affected is the function Add of the file /src/main/java/cms/web/action/template/ForumManageAction.java of the component API. The manipulation of the argument dirName leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Metrics
Affected Vendors & Products
References
History
Sun, 22 Jun 2025 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability classified as critical has been found in diyhi bbs 6.8. Affected is the function Add of the file /src/main/java/cms/web/action/template/ForumManageAction.java of the component API. The manipulation of the argument dirName leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
Title | diyhi bbs API ForumManageAction.java add path traversal | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-06-22T02:31:05.226Z
Updated: 2025-06-22T02:31:05.226Z
Reserved: 2025-06-20T19:29:40.312Z
Link: CVE-2025-6453

No data.

Status : Received
Published: 2025-06-22T03:15:31.490
Modified: 2025-06-22T03:15:31.490
Link: CVE-2025-6453

No data.