← back
CVE-2025-1743mediumobserved exploitationCWE-22

zyx0814 Pichome index.php path traversal

50Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 6.9epss 1.6%
from disclosure to weapon
Published on NVDFeb 27
VulnCheck+340d
exploitation probability
1.6%top 26% of all CVEs
observed exploitation
yesVulnCheck
A vulnerability, which was classified as critical, was found in zyx0814 Pichome 2.1.0. This affects an unknown part of the file /index.php?mod=textviewer. The manipulation of the argument src leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
zyx0814 · Pichome