YiJiuSmile kkFileViewOfficeEdit deleteFile path traversal
Published Jul 14, 2025
5.3
MEDIUMCVSS 4.0
EPSS 0.76%
Description
A vulnerability was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd. It has been classified as critical. This affects the function deleteFile of the file /deleteFile. The manipulation of the argument fileName leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.
Affected products
-
Affected
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| YiJiuSmile | kkFileViewOfficeEdit | unknown | Affected |
- ≤ 2019-03-19
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-21381 Advisory
- https://github.com/YiJiuSmile/kkFileViewOfficeEdit/issues/15 exploitissue-trackingIssue TrackingVendor Advisory
- https://vuldb.com/?ctiid.316329 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.316329 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.609098 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-21381 | Advisory | |
| https://github.com/YiJiuSmile/kkFileViewOfficeEdit/issues/15 | exploitissue-trackingIssue TrackingVendor Advisory | |
| https://vuldb.com/?ctiid.316329 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.316329 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.609098 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data