JeeWMS Path Traversal Vulnerability in cgformTemplateController.do?doAdd

Vulnerability

A critical path traversal vulnerability has been identified in JeeWMS versions prior to 20250504. The issue arises in the doAdd function of the cgformTemplateController, allowing remote attackers to manipulate file paths and potentially access restricted files.

Impact

Exploitation of this vulnerability allows for path traversal, which could lead to unauthorized file access on the server.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.8
exploitability
5.2
remediation
0.0
relevance
0.1
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.