CVE-2025-14018

HIGH

NetBT Consulting Services Inc. E-Fatura <1.2.15 - Path Traversal

Title source: llm

Description

Unquoted Search Path or Element vulnerability in NetBT Consulting Services Inc. E-Fatura allows Leveraging/Manipulating Configuration File Search Paths, Redirect Access to Libraries.This issue affects e-Fatura: before 1.2.15.

Exploits (1)

nomisec WRITEUP
by kaleth4 · poc
https://github.com/kaleth4/CVE-2025-14018

Scores

CVSS v3 7.3
EPSS 0.0029
EPSS Percentile 52.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

Details

CWE
CWE-428
Status published
Products (1)
NetBT Consulting Services Inc./e-Fatura < 1.2.15
Published Dec 22, 2025
Tracked Since Feb 18, 2026