CVE-2025-52922
Last modified
CVE-2025-52922 is a high-severity vulnerability rated 7.4/10 on the CVSS scale. Innoshop through 0.4.1 allows directory traversal via FileManager API endpoints. An authenticated attacker with access to the admin panel could abuse this to: (1) fully map the filesystem structure via the /api/file_manager/files?base_folder= endpoint, (2) create arbitrary directories on the server via the /api/file_manager/directories endpoint, (3) read arbitrary files from the server by copying the file to a readable location within the application via the /api/file_manager/copy_files endpoint, {4) delete arbitrary files from the server via a DELETE request to /api/file_manager/files, or (5) create arbitrary files on the server by uploading them and then leveraging the /api/file_manager/move_files endpoint to move them anywhere in the filesystem.. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
Innoshop through 0.4.1 allows directory traversal via FileManager API endpoints. An authenticated attacker with access to the admin panel could abuse this to: (1) fully map the filesystem structure via the /api/file_manager/files?base_folder= endpoint, (2) create arbitrary directories on the server via the /api/file_manager/directories endpoint, (3) read arbitrary files from the server by copying the file to a readable location within the application via the /api/file_manager/copy_files endpoint, {4) delete arbitrary files from the server via a DELETE request to /api/file_manager/files, or (5) create arbitrary files on the server by uploading them and then leveraging the /api/file_manager/move_files endpoint to move them anywhere in the filesystem.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-52922?
How severe is CVE-2025-52922?
How do I fix CVE-2025-52922?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-52917The Yealink RPS API before 2025-05-26 lacks rate limiting, p…4.3
- CVE-2025-52918Yealink RPS before 2025-05-26 does not prevent OpenAPI acces…5
- CVE-2025-52919In Yealink RPS before 2025-05-26, the certificate upload fun…4.3
- CVE-2025-5292The Element Pack Addons for Elementor – Best Elementor addon…6.4
- CVE-2025-52920Innoshop through 0.4.1 allows Insecure Direct Object Referen…6.4
- CVE-2025-52921In Innoshop through 0.4.1, an authenticated attacker could e…9.9
- CVE-2025-52923Sangfor aTrust through 2.4.10 allows users to modify the Exe…4.3
- CVE-2025-52924In One Identity OneLogin before 2025.2.0, the SQL connection…4
- CVE-2025-52925In One Identity OneLogin Active Directory Connector before 6…5
- CVE-2025-52926In scan.rs in spytrap-adb before 0.3.5, matches for known st…2.7
- CVE-2025-52930A memory corruption vulnerability exists in the BMPv3 RLE De…8.8
- CVE-2025-52931Mattermost Confluence Plugin version <1.5.0 fails to handle …7.5
Are you affected by CVE-2025-52922?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
