Record summary

CVE-2025-1035 has a selected CVSS score of 5.7 (medium); EIP currently links 1 Nuclei template.

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls. This issue affects KLog Server: before 3.1.1.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 18, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListBefore 3.1.1affected

Nuclei templates

1
ProjectDiscoveryMEDIUMKLog Server - Path TraversalCVSS 5.7

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls.This issue affects KLog Server: before 3.1.1.

Impact

Authenticated attackers can exploit path traversal vulnerabilities to read arbitrary files from the KLog Server, potentially exposing sensitive system files, configuration data, and stored logs.

Remediation

Upgrade to KLog Server version 3.1.1 or later that addresses the path traversal vulnerability.

WeaknessesCWE-22
Authorss4e-io
Template tagscvecve2025klog-serverlfivuln
CVSS vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Source: ProjectDiscovery

References

4