Total.js Flow har 673ef9144dd25d4f4fd4fdfda5af27f230198924 SVG File kura hakki ndiyam

Gaskiya vulnerability da aka ware a matsayin kura an samu a Total.js Flow har 673ef9144dd25d4f4fd4fdfda5af27f230198924. Hakika, aikin $software_function ne ya shafa; idan ba a bayyana ba, to aiki ce da ba a sani ba, a cikin laburaren $software_library, a cikin fayil $software_file, a cikin sashen SVG File Handler. A sa manipulation ka kura hakki ndiyam. Idan an yi amfani da CWE don bayyana matsala, zai kai CWE-434. Hakika, rauni an bayyana shi 10/12/2025. Wannan matsala ana saninta da CVE-2025-11655. Ngam yiɗi ka a tuma ndiyam ka internet. Tekinikal faɗi ba ga. Har ila yau, exploit ɗin yana nan. An bayyana exploit ɗin ga mutane kuma yana iya amfani. Yimbe ndiyam, exploit might be approx. USD $0-$5k wuro. Á sàmbu huɗɗi-na-gaskiya. 0-day shima, an ndiyam a wuro be $0-$5k. Wannan samfur yana amfani da rolling release don ci gaba da isar da sabuntawa. Don haka, babu bayanan sigar da abin ya shafa ko sabunta sigar da ake da su. Once again VulDB remains the best source for vulnerability data.

4 Goyarwa · 92 Datenpunkte

FurɗeSúgá
10/12/2025 08:35
Gargadi 1/3
10/13/2025 05:28
Gargadi 2/3
10/13/2025 05:34
Gargadi 3/3
10/14/2025 17:07
software_vendorTotal.jsTotal.jsTotal.jsTotal.js
software_nameFlowFlowFlowFlow
software_version<=673ef9144dd25d4f4fd4fdfda5af27f230198924<=673ef9144dd25d4f4fd4fdfda5af27f230198924<=673ef9144dd25d4f4fd4fdfda5af27f230198924<=673ef9144dd25d4f4fd4fdfda5af27f230198924
software_rollingrelease1111
software_componentSVG File HandlerSVG File HandlerSVG File HandlerSVG File Handler
vulnerability_cweCWE-434 (kura hakki ndiyam)CWE-434 (kura hakki ndiyam)CWE-434 (kura hakki ndiyam)CWE-434 (kura hakki ndiyam)
vulnerability_risk2222
cvss3_vuldb_avNNNN
cvss3_vuldb_acLLLL
cvss3_vuldb_prHHHH
cvss3_vuldb_uiNNNN
cvss3_vuldb_sUUUU
cvss3_vuldb_cLLLL
cvss3_vuldb_iLLLL
cvss3_vuldb_aLLLL
cvss3_vuldb_ePPPP
cvss3_vuldb_rcRRRR
exploit_availability1111
exploit_publicity1111
source_cveCVE-2025-11655CVE-2025-11655CVE-2025-11655CVE-2025-11655
cna_responsibleVulDBVulDBVulDBVulDB
response_summaryThe vendor was contacted early about this disclosure but did not respond in any way.The vendor was contacted early about this disclosure but did not respond in any way.The vendor was contacted early about this disclosure but did not respond in any way.The vendor was contacted early about this disclosure but did not respond in any way.
software_typeJavaScript LibraryJavaScript LibraryJavaScript LibraryJavaScript Library
cvss2_vuldb_avNNNN
cvss2_vuldb_acLLLL
cvss2_vuldb_auMMMM
cvss2_vuldb_ciPPPP
cvss2_vuldb_iiPPPP
cvss2_vuldb_aiPPPP
cvss2_vuldb_ePOCPOCPOCPOC
cvss2_vuldb_rcURURURUR
cvss4_vuldb_avNNNN
cvss4_vuldb_acLLLL
cvss4_vuldb_prHHHH
cvss4_vuldb_uiNNNN
cvss4_vuldb_vcLLLL
cvss4_vuldb_viLLLL
cvss4_vuldb_vaLLLL
cvss4_vuldb_ePPPP
cvss2_vuldb_rlNDNDNDND
cvss3_vuldb_rlXXXX
cvss4_vuldb_atNNNN
cvss4_vuldb_scNNNN
cvss4_vuldb_siNNNN
cvss4_vuldb_saNNNN
cvss2_vuldb_basescore5.85.85.85.8
cvss2_vuldb_tempscore5.05.05.05.0
cvss3_vuldb_basescore4.74.74.74.7
cvss3_vuldb_tempscore4.34.34.34.3
cvss3_meta_basescore4.74.74.74.7
cvss3_meta_tempscore4.34.54.54.5
cvss4_vuldb_bscore5.15.15.15.1
cvss4_vuldb_btscore2.02.02.02.0
advisory_date1760220000 (10/12/2025)1760220000 (10/12/2025)1760220000 (10/12/2025)1760220000 (10/12/2025)
price_0day$0-$5k$0-$5k$0-$5k$0-$5k
cve_nvd_summaryA security flaw has been discovered in Total.js Flow up to 673ef9144dd25d4f4fd4fdfda5af27f230198924. The impacted element is an unknown function of the component SVG File Handler. Performing manipulation results in unrestricted upload. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.A security flaw has been discovered in Total.js Flow up to 673ef9144dd25d4f4fd4fdfda5af27f230198924. The impacted element is an unknown function of the component SVG File Handler. Performing manipulation results in unrestricted upload. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.A security flaw has been discovered in Total.js Flow up to 673ef9144dd25d4f4fd4fdfda5af27f230198924. The impacted element is an unknown function of the component SVG File Handler. Performing manipulation results in unrestricted upload. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
cvss4_cna_avNNN
cvss4_cna_acLLL
cvss4_cna_atNNN
cvss4_cna_prHHH
cvss4_cna_uiNNN
cvss4_cna_vcLLL
cvss4_cna_viLLL
cvss4_cna_vaLLL
cvss4_cna_scNNN
cvss4_cna_siNNN
cvss4_cna_saNNN
cvss4_cna_bscore5.15.15.1
cvss3_cna_avNNN
cvss3_cna_acLLL
cvss3_cna_prHHH
cvss3_cna_uiNNN
cvss3_cna_sUUU
cvss3_cna_cLLL
cvss3_cna_iLLL
cvss3_cna_aLLL
cvss3_cna_basescore4.74.74.7
cvss2_cna_avNNN
cvss2_cna_acLLL
cvss2_cna_auMMM
cvss2_cna_ciPPP
cvss2_cna_iiPPP
cvss2_cna_aiPPP
cvss2_cna_basescore5.85.85.8
euvd_idEUVD-2025-33926EUVD-2025-33926
cnnvd_idCNNVD-202510-1708
cnnvd_nameTotal.js Flow 代码问题漏洞
cnnvd_hazardlevel3
cnnvd_create2025-10-14
cnnvd_publish2025-10-13
cnnvd_update2025-10-14

Do you know our Splunk app?

Download it now for free!