Showing 1 vulnerability on this page for WeiPHP

Signals CISA KEV Ransomware Nuclei
Shenzhen Yuanmengyun Technology Co., Ltd vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WeiPHP Path Traversal Arbitrary File Read

A path traversal vulnerability exists in WeiPHP 5.0, an open source WeChat public account platform development framework by Shenzhen Yuanmengyun Technology Co., Ltd. The flaw occurs in the picUrl parameter of the /public/index.php/material/Material/_download_imgage endpoint, where insufficient input validation allows unauthenticated remote attackers to perform directory traversal via crafted POST requests. This enables arbitrary file read on the server, potentially exposing sensitive information

CWE-20CWE-22Jun 26, 20251 related artifact
CVSS8.7v4.0EPSS4.31%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX