CVE-2025-1743
zyx0814 Pichome index.php path traversal
Record summary
CVE-2025-1743 has a selected CVSS score of 6.9 (medium); EIP currently links 1 Nuclei template.
Description
A vulnerability, which was classified as critical, was found in zyx0814 Pichome 2.1.0. This affects an unknown part of the file /index.php?mod=textviewer. The manipulation of the argument src leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Feb 2, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 27, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
PichomeBrowse zyx0814 / Pichome | CVE List, VulnCheck | 2.1.0 | affected |
Nuclei templates
1ProjectDiscoveryHIGHPichome 2.1.0 - Arbitrary File ReadCVSS 5.3
A vulnerability, which was classified as critical, was found in zyx0814 Pichome 2.1.0. This affects an unknown part of the file /index.php?mod=textviewer. The manipulation of the argument src leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Impact
Unauthenticated attackers can read arbitrary files from the server through path traversal in the src parameter, potentially exposing sensitive configuration files, credentials, and user data.
Remediation
Upgrade to Pichome version 2.1.1 or later that properly validates file paths.
Source: ProjectDiscovery