CVE-2025-1035
Path Traversal in Komtera Technolgies' KLog Server
Record summary
CVE-2025-1035 has a selected CVSS score of 5.7 (medium); EIP currently links 1 Nuclei template.
Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls. This issue affects KLog Server: before 3.1.1.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 18, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
KLog ServerBrowse Komtera Technolgies / KLog ServerDefault status: unaffected | CVE List | Before 3.1.1 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMKLog Server - Path TraversalCVSS 5.7
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls.This issue affects KLog Server: before 3.1.1.
Impact
Authenticated attackers can exploit path traversal vulnerabilities to read arbitrary files from the KLog Server, potentially exposing sensitive system files, configuration data, and stored logs.
Remediation
Upgrade to KLog Server version 3.1.1 or later that addresses the path traversal vulnerability.
Source: ProjectDiscovery